Executive brief
Microsoft Windows NT systems may contain local user or administrator accounts configured with default, blank, or missing passwords. This allows an unauthorized person to easily log into the system with the privileges of that account. Depending on the account type, this could lead to a complete takeover of the computer, theft of sensitive data, or disruption of business operations.
Technical details
The vulnerability stems from insecure default configurations or administrative oversight where local user or administrator accounts on Windows NT are left with null, blank, or default passwords. This is a credential-based weakness rather than a software bug. An attacker with network or local access can authenticate to the system without providing a valid secret, potentially gaining full administrative control if the affected account has elevated privileges. This issue is typically mitigated by enforcing strong password policies and auditing local account databases for weak credentials.
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed