The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin (MS01-001) - Patch Available for "Web Client NTLM Authentication" Vulnerability
Time: 20:13 EST/01:13 GMT | News Source: Microsoft TechNet Security | Posted By: Will1

Microsoft has released a patch that eliminates a security vulnerability in a component that ships with Microsoft® Office 2000, Windows 2000, and Windows Me. The vulnerability could, under certain circumstances, allow a malicious user to obtain cryptographically protected logon credentials from another user when requesting an Office document from a web server.

The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to an implementation flaw, WEC does not respect the IE Security settings regarding when NTLM authentication will be performed – instead, WEC will perform NTLM authentication with any server that requests it. If a user established a session with a malicious user’s web site – either by browsing to the site or by opening an HTML mail that initiated a session with it – an application on the site could capture the user’s NTLM credentials. The malicious user could then use an offline brute force attack to derive the password or, with specialized tools, could submit a variant of these credentials in an attempt to access protected resources.

The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, allow a malicious user to gain control of another user’s computer or to gain access to resources to which that user was authorized access. In order to leverage the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely logon to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices were followed, they would prevent an attacker from using the credentials to logon to the target system.

Affected Software Versions:

  • Microsoft Office 2000
  • Microsoft Windows 2000
  • Microsoft Windows Me

Patch Availability:

Note: Since the affected component ships with the above products independent of Office 2000, we have provided patches for affected systems that may not be running Office 2000. As discussed in the FAQ, the patch and vulnerability only affect machines running Internet Explorer 5.0 or later with Web Folders enabled.

Write Comment
Return to News

  Displaying 301 through 311 of 311
Prev | First
  The time now is 6:11:03 AM ET.
Any comment problems? E-mail us
#301 By 4240821 (166.1.149.158) at 11/22/2024 10:58:24 PM
https://www.google.hr/amp/s/sexonly.top/get/a99/a99zktdekgmbhjyxjw.php
https://www.google.ht/amp/s/nsfw.su/get/a213/a213jyxxjauszayuioh.php
https://www.google.hr/amp/s/sexonly.su/get/a90/a90ggyqxiaskzztwxo.php
https://www.google.hu/amp/s/sluts.su/get/a173/a173vfzpdbhooemfbzr.php
https://www.google.ht/amp/s/sexonly.top/get/a251/a251vfnwkbkfrtecphe.php
https://www.google.im/amp/s/sexonly.su/get/a246/a246dlgguzvqggjinkr.php
https://www.google.hu/amp/s/sexonly.su/get/a126/a126wnoxdedipytcboz.php
https://www.google.im/amp/s/nsfw.su/get/a120/a120qqxukxsspnvwdnk.php
https://www.google.ht/amp/s/sexonly.top/get/a55/a55tsytcuxgcvsvxgr.php
https://www.google.is/amp/s/sexonly.su/get/a261/a261daiauqvrobxflnh.php

#302 By 4240821 (166.1.149.158) at 11/23/2024 12:14:30 AM
https://www.google.gm/amp/s/sexonly.top/get/a43/a43hjqkiojiqsvgwvy.php
https://www.google.fr/amp/s/lustful.su/get/a124/a124ebgvizpumxsrbvi.php
https://www.google.gy/amp/s/sexonly.su/get/a79/a79srwupoowzcpedqi.php
https://www.google.gg/amp/s/lustful.su/get/a275/a275eeguplwvoggxtgp.php
https://www.google.gm/amp/s/sexonly.su/get/a149/a149esmtcsgtzijkvnn.php
https://www.google.fr/amp/s/sexonly.su/get/a78/a78ocnbnuruceelbuk.php
https://www.google.gm/amp/s/sluts.su/get/a102/a102dkcznuilayujdlp.php
https://www.google.gr/amp/s/sexonly.su/get/a99/a99seqcpljhgpyswbo.php
https://www.google.gp/amp/s/sluts.su/get/a200/a200kfvhllrfvwuceqm.php
https://www.google.gr/amp/s/lustful.su/get/a147/a147qhcuhdwgjplshfa.php

#303 By 4240821 (82.117.86.164) at 11/23/2024 6:36:06 AM
https://www.google.mg/amp/s/sluts.su/get/a74/a74ljxwisydfsofbmk.php
https://www.google.ml/amp/s/sluts.su/get/a143/a143stwwypinhobshjq.php
https://www.google.lv/amp/s/lustful.su/get/a63/a63vcoxwwkcfmitczq.php
https://www.google.lv/amp/s/sexonly.su/get/a211/a211pbqorsuaxhcokuk.php
https://www.google.lv/amp/s/sluts.su/get/a204/a204ssiepzcymzvdyac.php
https://www.google.md/amp/s/nsfw.su/get/a116/a116hjeckjfljykyhwi.php
https://www.google.mk/amp/s/lustful.su/get/a222/a222mgxcipbwiyycwgz.php
https://www.google.mn/amp/s/sluts.su/get/a269/a269idxiqclxzuxpowo.php
https://www.google.mg/amp/s/lustful.su/get/a133/a133hsqyqftrquvntcq.php
https://www.google.mk/amp/s/lustful.su/get/a264/a264wqvmvzpoltbalxx.php

#304 By 4240821 (62.76.153.72) at 11/23/2024 4:24:46 PM
https://justpaste.me/Bcyt5
https://justpaste.me/CPHY1
https://justpaste.me/Bcyt5
https://justpaste.me/BcSI1
https://justpaste.me/CTi3
https://justpaste.me/C4QT1
https://justpaste.me/C6OU1
https://justpaste.me/CYC21
https://justpaste.me/BfQa2
https://justpaste.me/BcSI1

#305 By 4240821 (212.193.138.162) at 11/24/2024 2:39:13 AM
https://www.google.nl/amp/s/nsfw.su/get/a80/a80wultmdnafqhhnbt.php
https://www.google.ng/amp/s/nsfw.su/get/a282/a282pvdfhfzrlpugxgm.php
https://www.google.mw/amp/s/sexonly.top/get/a55/a55chyyixlfwhokaly.php
https://www.google.pk/amp/s/sluts.su/get/a104/a104qwiurfyukmswteo.php
https://www.google.mv/amp/s/sexonly.top/get/a83/a83gurfhsivdlbawzt.php
https://www.google.mx/amp/s/lustful.su/get/a207/a207zuinctjpclofnga.php
https://www.google.no/amp/s/sexonly.su/get/a175/a175vglczrndrvarumm.php
https://www.google.no/amp/s/nsfw.su/get/a171/a171ktncdtyuccvscmz.php
https://www.google.nl/amp/s/sluts.su/get/a71/a71qexkexlwvuxgdrk.php
https://www.google.mx/amp/s/lustful.su/get/a237/a237xsgantcukmlmqtd.php

#306 By 4240821 (62.76.153.72) at 11/24/2024 10:24:05 AM
https://justpaste.me/CCxC1
https://justpaste.me/BhC03
https://justpaste.me/BejG
https://justpaste.me/CLW91
https://justpaste.me/BlRN2
https://justpaste.me/C2Zc1
https://justpaste.me/CQul
https://justpaste.me/CKGJ2
https://justpaste.me/C43t
https://justpaste.me/C9Tk2

#307 By 4240821 (77.83.4.69) at 11/25/2024 1:41:52 AM
https://justpaste.me/CCbO2
https://justpaste.me/BjiY3
https://justpaste.me/Beu33
https://justpaste.me/CLt0
https://justpaste.me/Bp5B
https://justpaste.me/CP80
https://justpaste.me/CUOs4
https://justpaste.me/CcwW3
https://justpaste.me/BcSI1
https://justpaste.me/C6jm

#308 By 4240821 (212.193.138.162) at 11/25/2024 6:29:52 PM
https://www.google.at/amp/s/sluts.su/get/a218/a218slmthsmpkkbgryu.php
https://www.google.ad/amp/s/lustful.su/get/a217/a217adnhvokrgugtyit.php
https://www.google.ac/amp/s/sexonly.top/get/a223/a223zzqnjbimcpgqoff.php
https://www.google.ac/amp/s/lustful.su/get/a43/a43axnzlumeskclbcf.php
https://www.google.am/amp/s/sexonly.su/get/a56/a56mhnlszhlkhwnxgq.php
https://www.google.am/amp/s/lustful.su/get/a125/a125bfroyhsrfwejvad.php
https://www.google.ad/amp/s/sexonly.top/get/a184/a184sabbfasinwkwoks.php
https://www.google.ad/amp/s/nsfw.su/get/a259/a259ofhbmnzcklfwdqk.php
https://www.google.af/amp/s/nsfw.su/get/a32/a32qtdmaawnmzrbosy.php
https://www.google.com/amp/s/sluts.su/get/a115/a115clcqrkingobbjlg.php

#309 By 4240821 (77.83.4.69) at 11/25/2024 9:36:11 PM
https://www.google.ru/amp/s/lustful.su/get/a89/a89rdmnqhzxhscizqd.php
https://www.google.rs/amp/s/sexonly.top/get/a172/a172ufdjyparbwmsgwb.php
https://www.google.se/amp/s/nsfw.su/get/a4/a4lxorpwrxshpjsdr.php
https://www.google.ro/amp/s/sexonly.top/get/a135/a135fsothfzaeqnzjmj.php
https://www.google.rs/amp/s/sexonly.su/get/a155/a155taeqcdxyxlntxbg.php
https://www.google.ru/amp/s/nsfw.su/get/a115/a115wglnyxkuepamvat.php
https://www.google.se/amp/s/lustful.su/get/a87/a87fugwzpxgecqdvdj.php
https://www.google.pl/amp/s/nsfw.su/get/a23/a23dlbkkpfibfxfhzg.php
https://www.google.ps/amp/s/sluts.su/get/a17/a17grpnstipfguorjl.php
https://www.google.pt/amp/s/nsfw.su/get/a178/a178eldolyxqwzfhkdj.php

#310 By 4240821 (212.193.138.162) at 11/26/2024 6:53:50 AM
https://justpaste.me/CQMj2
https://justpaste.me/CRw5
https://justpaste.me/BsVj3
https://justpaste.me/C4mH1
https://justpaste.me/CWGO
https://justpaste.me/BoXc1
https://justpaste.me/Bs5M1
https://justpaste.me/CA04
https://justpaste.me/CL9j2
https://justpaste.me/CIFX2

#311 By 4240821 (77.83.6.99) at 11/27/2024 1:12:56 AM
https://www.google.tk/amp/s/sexonly.top/get/a57/a57ofsxxcmkwqhopwc.php
https://www.google.tg/amp/s/sexonly.top/get/a163/a163yvznblwachbapgh.php
https://www.google.sk/amp/s/sexonly.su/get/a219/a219dakwgnaxaoysywy.php
https://www.google.so/amp/s/sexonly.top/get/a55/a55xwyghycseopmlrh.php
https://www.google.td/amp/s/lustful.su/get/a108/a108sgmjnidnyqtoliz.php
https://www.google.td/amp/s/nsfw.su/get/a145/a145imkhcouhoweagqs.php
https://www.google.tg/amp/s/sexonly.su/get/a185/a185jpiyzdqhibadpbl.php
https://www.google.tk/amp/s/sluts.su/get/a139/a139mexvmmnymouwikc.php
https://www.google.sn/amp/s/sexonly.top/get/a225/a225uwggxfoajnwcxcr.php
https://www.google.td/amp/s/lustful.su/get/a216/a216xpikldyhjnbawja.php

Write Comment
Return to News
  Displaying 301 through 311 of 311
Prev | First
  The time now is 6:11:03 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *