Microsoft Windows 2000 EFS Vulnerability

BID:539

Info

Microsoft Windows 2000 EFS Vulnerability

Bugtraq ID: 539
Class: Unknown
CVE:
Remote: No
Local: Yes
Published: Jul 25 1999 12:00AM
Updated: Jul 25 1999 12:00AM
Credit: "Windows 2000 Encrypting File System (EFS) Vulnerability" paper released July 25 by James J. Grace <[email protected]> and Thomas S. V. Bartlett III <[email protected]>. Posted to Bugtraq July 26, 1999 by Matt <[email protected]>. Microsoft's reply posted to NTBug
Vulnerable: Microsoft Windows 2000 Server
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Advanced Server
Not Vulnerable:

Exploit / POC

Microsoft Windows 2000 EFS Vulnerability

Quoted verbatim from James J. Grace's paper "Windows 2000 Encrypting File System (EFS) Vulnerability" released July 25, 1999:

For member servers or workstations do the following:
-Install a second (parallel) copy of Windows NT 2000 onto the computer system. If there is not enough hard disk space use a third party utility to delete unneeded files to make space. Install this copy into say c:\winnt2.
-Boot the computer to the copy of NT installed into the c:\winnt2 directory.
-Using Windows Explorer locate the c:\winnt\system32\config directory.
-Make a backup copy of all the files located in c:\winnt\system32\config.
-In the c:\winnt\system32\config directory locate and delete the SAM and SAM.LOG files.
-Shutdown and reboot the computer into the c:\winnt directory (This is the original servers installation)
-At the logon screen press CTL+ALT+DEL.
-Enter Administrator for the user name.
-Press the enter key for the password. (No Password)
-The system now logs you on as administrator.
-Using Windows Explorer, locate the encrypted files and open them. EFS will automatically decrypt the files for you.
-At this point you are able to access all files encrypted or plaintext on the server.

For Active Directory Services Domain Controllers do the following:
(For the purpose of this discussion assume Windows NT 2000 was installed into c:\winnt)
-Install a second (parallel) copy of Windows NT 2000 onto the computer system. If there is not enough hard disk space use a third party utility to delete unneeded files to make space. Install this copy into say c:\winnt2.
-Boot the computer to the copy of NT installed into the c:\winnt2 directory.
-Using Windows Explorer locate the c:\winnt\system32\config directory.
-Make a backup copy of all the files located in c:\winnt\system32\config.
-In the c:\winnt\system32\config directory locate and delete the SAM and SAM.LOG files.
-Shutdown and reboot the computer.
-As the NTLDR boots and the BOOT.INI menu is presented press the F8 key to boot the server into Safe Recovery Mode
-Select Active Directory Services Recovery from the menu.
-Select the original server installation
-The system will now boot into safe mode
-At the logon screen press CTL+ALT+DEL.
-Enter Administrator for the user name.
-Press the enter key for the password. (No Password)
-The system now logs you on as administrator.
-Using Windows Explorer, locate the encrypted files and open them. EFS will automatically decrypt the files for you.
-At this point all data on the servers has been compromised.

Solution / Fix

Microsoft Windows 2000 EFS Vulnerability

Solution:
Microsoft strongly recommends storing the recovery key off the system, choosing a user besides administrator as the RA, and using syskey.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report