advanced search
down64.com >>  Utilities :: Patches and Updates >> Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability
Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability MS01-001

    The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to an implementation flaw, WEC does not respect the IE Security settings regarding when NTLM authentication will be performed ? instead, WEC will perform NTLM authentication with any server that requests it. If a user established a session with a malicious user???s web site ? either by browsing to the site or by opening an HTML mail that initiated a session with it ? an application on the site could capture the user???s NTLM credentials. The malicious user could then use an offline brute force attack to derive the password or, with specialized tools, could submit a variant of these credentials in an attempt to access protected resources. The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, allow a malicious user to gain control of another user???s computer or to gain access to resources to which that user was authorized access. In order to leverage the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely logon to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices were followed, they would prevent an attacker from using the credentials to logon to the target system. This download is for Windows ME (without Office 2000 installed).

License: Freeware
File size: 305 KB
Date updated: 01/15/2001
Developer: Microsoft Corp. (More Products ...)
Homepage: www.microsoft.com

Download:  Download Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability
Award:


Bookmark:
Text Link: Copy
Html Link: Copy
 
Popular search terms related to Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability:
   Microsoft
   Windows
   Me
   Security
   Patch
   Web
   Client
   Authentication
   Vulnerability

Related keywords:
   brute-force
   logon
   office 2000
   attack
   microsoft office
   submit

Products of Microsoft Corp., 17 Programs, Show All
Title Date Size
Microsoft Office 2000 SR-1 Update: Web Client Security MS01-001
The Web Client Security Update for Office 2000 protects you from a vulnerability in Office 2000 that can allow login information to be sent over the Internet. Malicious Web site operators could deceive users into browsing to a Web page or server that...
2001-01-15733 KB
Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability MS01-001
The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to...
2001-01-15305 KB
Microsoft Access 2000 and SQL Server 2000 Readiness Update 12-21-00
The Access 2000 and SQL Server 2000 Readiness Update improves the way in which Microsoft Access 2000 works with Microsoft SQL Server 2000. This update allows you to upsize Access databases to SQL Server 2000, and to create new databases against SQL S...
2000-12-28640 KB
Microsoft Windows Media Services 4.0 & 4.1 Security Patch: 'Severed Windows Media Server Connection' Vulnerability 12-15-00
If a connection to a server running the Windows Media Unicast Service was started, then severed, in a particular way, the service would ???leak??? some of the resources that were allocated during the connection. If this sequence of commands was repeated ...
2000-12-20650 KB
Microsoft SQL Server 2000 (including MS SQL Server Desktop Engine 2000) Security Patch: 'Extended Stored Procedure Param 12-1-00
This is a buffer overrun vulnerability. A malicious user could exploit this vulnerability in either of two ways. In the simplest case, he or she could use the vulnerability to cause the SQL Server service to fail. In the more complex case, he or she ...
2000-12-04235 KB
Submit Software | Privacy Policy | Terms of Use | Advertise with Us | Awards | Developer | Link to Us | Links | Contact Us
Copyright © down64.com. All rights reserved.

Partner Sites:  Addicting Games  IE Picture Downloader  Free Computer Software  Funny jokes