Executive brief
Microsoft Windows NT systems are susceptible to unauthorized access because local user or administrator accounts may use weak, easily guessable passwords. An attacker with physical or local access to the machine could gain full control over the system by guessing these credentials. This could lead to the theft of sensitive data, installation of malicious software, or complete disruption of the computer's operations.
Technical details
The vulnerability stems from the use of weak or default credentials for local accounts on Microsoft Windows NT. An attacker with local access can perform brute-force or dictionary attacks to guess account passwords. Successful exploitation grants the attacker the privileges associated with the compromised account, which in the case of an administrator account, results in complete control over the operating system (C:C/I:C/A:C). This is a configuration-based weakness rather than a software bug, but it is tracked as a vulnerability due to the high impact of default or easily guessed administrative credentials.
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed