Executive brief
Microsoft Windows NT systems may be configured with weak password policies that fail to meet security standards. This can include insufficient requirements for password length, age, or uniqueness, making it significantly easier for unauthorized individuals to guess or crack user credentials. If exploited, an attacker could gain full administrative control over the system, leading to total data exposure and operational disruption.
Technical details
This entry describes a configuration-based vulnerability where Windows NT account policies are set to insecure values. Specifically, the policy may lack adequate enforcement for minimum password length, maximum password age, or password history (uniqueness). An attacker can leverage these weak requirements to perform brute-force or credential-guessing attacks more effectively. Because this is a policy configuration issue rather than a code flaw, the primary remediation is for administrators to manually harden the account policy settings within the operating system. Successful exploitation can lead to complete system compromise (Full Confidentiality, Integrity, and Availability impact).
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed