The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin (MS01-001) - Patch Available for "Web Client NTLM Authentication" Vulnerability
Time: 20:13 EST/01:13 GMT | News Source: Microsoft TechNet Security | Posted By: Will1

Microsoft has released a patch that eliminates a security vulnerability in a component that ships with Microsoft Office 2000, Windows 2000, and Windows Me. The vulnerability could, under certain circumstances, allow a malicious user to obtain cryptographically protected logon credentials from another user when requesting an Office document from a web server.

The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to an implementation flaw, WEC does not respect the IE Security settings regarding when NTLM authentication will be performed instead, WEC will perform NTLM authentication with any server that requests it. If a user established a session with a malicious users web site either by browsing to the site or by opening an HTML mail that initiated a session with it an application on the site could capture the users NTLM credentials. The malicious user could then use an offline brute force attack to derive the password or, with specialized tools, could submit a variant of these credentials in an attempt to access protected resources.

The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, allow a malicious user to gain control of another users computer or to gain access to resources to which that user was authorized access. In order to leverage the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely logon to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices were followed, they would prevent an attacker from using the credentials to logon to the target system.

Affected Software Versions:

  • Microsoft Office 2000
  • Microsoft Windows 2000
  • Microsoft Windows Me

Patch Availability:

Note: Since the affected component ships with the above products independent of Office 2000, we have provided patches for affected systems that may not be running Office 2000. As discussed in the FAQ, the patch and vulnerability only affect machines running Internet Explorer 5.0 or later with Web Folders enabled.

Write Comment
Return to News

  Displaying 701 through 708 of 708
Prev | First
  The time now is 12:54:15 PM ET.
Any comment problems? E-mail us
#701 By 4240821 (82.115.4.230) at 11/20/2025 1:30:35 AM
https://sluts.su/activbb51c222fe
https://smutty.su/activ554e23bb24
https://sexonly.su/activdda33af34h
https://nsfw.su/activebde53efhg
https://sexonly.su/activf5bbee54f2
https://nsfw.su/activ5fd2g4ac4b
https://sexonly.su/active433a31ge5
https://sluts.su/activf1gcgeb4ff
https://smutty.su/activbgfb144h3a
https://sexonly.top/activ2bhgcgbebg

#702 By 4240821 (45.192.45.37) at 11/20/2025 11:27:25 AM
https://telegra.ph/lakers--jazz-ignite-a-high-octane-showdown-with-a-buzzer-beater-finish-11-19-7
https://telegra.ph/Weather-ignites-fiery-debate-as-climate-extremes-redefine-our-planets-future-11-19-5
https://telegra.ph/Minka-Kelly-Steals-the-Spotlight-in-Stunning-New-Cover-Shoot-11-19
https://telegra.ph/weihnachtsmarkt-duisburg-lights-up-the-city-with-festive-frenzy-and-holiday-magic-11-19
https://telegra.ph/catherine-lucey-drops-a-jaw-dropping-exclusive-that-has-the-internet-buzzing-11-19-4
https://telegra.ph/catherine-lucey-drops-a-jaw-dropping-exclusive-that-has-the-internet-buzzing-11-19-3
https://telegra.ph/Miguel-Angel-Aguilar-Unveils-Groundbreaking-Innovation-Set-to-Transform-the-Industry-11-19
https://telegra.ph/curacao-Craze-Why-This-Caribbean-Jewel-Is-Taking-Social-Media-by-Storm-11-19-5
https://telegra.ph/WI-vs-NZ-Caribbean-Firestorm-Drowns-Kiwis-11-19
https://telegra.ph/region-østdanmark-valgresultat-Upends-Danish-Politics-as-the-Nation-Watches-in-Shock-11-19

#703 By 4240821 (82.115.4.230) at 11/21/2025 1:52:57 AM
https://nsfw.su/activd153h34c4f
https://lustful.su/activh3c12e2gcd
https://smutty.su/activbb41d14fh3
https://nsfw.su/activf54f14323c
https://sexonly.su/activdddb345eg1
https://sexonly.top/activ43ab1c2dg4
https://lustful.su/activ4gha5h52a4
https://sexonly.top/activh51a54333f
https://nsfw.su/activ1h5441523f
https://nsfw.su/activbgd4d31cbd

#704 By 4240821 (45.192.45.37) at 11/21/2025 11:49:19 PM
https://telegra.ph/malice-tv-show-explodes-online-as-ruthless-twists-rewrite-the-rules-of-streaming-drama-11-14
https://telegra.ph/Patriots-vs-Jets-Game-of-the-Week-11-14-6
https://telegra.ph/Japans-Surprise-Victory-Over-Ghana-in-Thrilling-World-Cup-Showdown-11-14
https://telegra.ph/Bitcoin-Kurs-Surges-to-Record-Highs-Amid-Investor-Euphoria-11-14
https://telegra.ph/damien-rieu-goes-viral-after-shocking-reveal-that-electrifies-the-internet-11-14-2
https://telegra.ph/Jayant-Patel-Breakthrough-Transforming-Healthcare-with-Unmatched-Innovation-11-14
https://telegra.ph/Beatrice-Arneras-Shocking-Comeback-From-Tragedy-to-Triumph-11-14
https://telegra.ph/south-korea-vs-bolivia-explosive-showdown-sparks-nail-biting-battle-on-the-world-stage-11-14
https://telegra.ph/UEFA-VM-Kvalifikation-Last-Minute-Drama-as-Croatia-Secures-Historic-Win-Over-England-11-14
https://telegra.ph/Sri-Lanka-Faces-Off-Against-Pakistan-in-Thrilling-Cricket-Showdown-11-14-2

#705 By 4240821 (178.217.45.42) at 11/24/2025 9:15:28 AM
https://nsfw.su/activg1dd5ag54c
https://sexonly.su/activhe43c14f22
https://smutty.su/activ45egfb14a3
https://lustful.su/activhaf1d5bcea
https://sluts.su/activde11d15cch
https://nsfw.su/activhf135hd333
https://sexonly.su/active14bhh5cgd
https://sluts.su/activg2a2ggd2d3
https://lustful.su/activcg2fcbeh22
https://lustful.su/activ2efh2hfgb1

#706 By 4240821 (45.192.45.37) at 11/24/2025 9:33:16 AM
https://telegra.ph/Underdog-Triumphs-in-Thrilling-Sports-Showdown-Shocking-the-World-11-21-3
https://telegra.ph/bangladesh-earthquake-today-leaves-city-in-chaos-as-rescue-teams-race-against-time-11-21-2
https://telegra.ph/Retail-World-Goes-Wild-as-vendredi-fou-2025-Ignites-Global-Shopping-Frenzy-11-21-2
https://telegra.ph/Wordle-Hint-for-Nov-21-Uncover-the-Mystery-Word-11-21
https://telegra.ph/Brive-Festival-Ignites-Summer-with-Unforgettable-Lineup-and-Explosive-Atmosphere-11-21
https://telegra.ph/Nikki-Haley-Surprises-Nation-with-Bold-New-Political-Shift-11-21
https://telegra.ph/Retail-World-Goes-Wild-as-vendredi-fou-2025-Ignites-Global-Shopping-Frenzy-11-21
https://telegra.ph/Heatwave-Havoc-الطقس-Unleashes-Record-Breaking-Temps-Worldwide-11-21-2
https://telegra.ph/musikhjälpen-2025-The-Night-the-World-Tuned-In-to-Fight-for-a-Cause-11-21
https://telegra.ph/josef-fares-drops-a-mind-bending-project-that-flips-the-script-11-21

#707 By 4240821 (45.192.45.37) at 11/24/2025 9:30:20 PM
https://telegra.ph/Clippers-Set-to-Clash-with-Mavericks-in-Thrilling-Showdown-for-NBA-Supremacy-11-15-2
https://telegra.ph/Keith-Richards-Shocking-Reveal-The-Truth-About-His-Iconic-Guitar-11-15
https://telegra.ph/solden-Sparks-Shopping-Frenzy-as-Limited-Edition-Drops-Vanish-in-Minutes-11-15
https://telegra.ph/bombenentschärfung-kiel-Tense-Hour-Ends-as-Authorities-Clear-Kiel-of-Threat-11-15
https://telegra.ph/Massive-Celebrations-Set-for-17-listopadu-Obchody-Spark-City-Wide-Festivities-11-15
https://telegra.ph/Strawberry-Festival-2026-Ignites-a-Berry-Burst-Weekend-of-Flavor-Fun-and-Fireworks-11-15
https://telegra.ph/Slovensko-vs-Severní-Irsko-Úžasné-přátelství-které-překračuje-hranice-11-15
https://telegra.ph/Guy-Rouxs-Culinary-Masterclass-A-Feast-for-the-Senses-11-15
https://telegra.ph/Nadia-Calviños-Shock-Plan-Rocks-EU-Financial-Markets-11-15
https://telegra.ph/Kelvin-Fletchers-Shocking-Confession-The-Truth-Behind-His-Mysterious-Disappearance-11-15

#708 By 4240821 (82.115.4.230) at 11/25/2025 6:52:32 AM
https://sexonly.su/activa4d41b4aed
https://sexonly.su/activ553gh1h4ah
https://sluts.su/activ4eg52h2412
https://smutty.su/activ2hfe4hg1ae
https://sluts.su/activchdc3132a1
https://sluts.su/activ4dbab2edcb
https://lustful.su/activf5e1gehgha
https://smutty.su/activb541fdbeca
https://sluts.su/activ354a3fgecc
https://lustful.su/activccg55cdh1g

Write Comment
Return to News
  Displaying 701 through 708 of 708
Prev | First
  The time now is 12:54:15 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *