Executive brief
Microsoft Windows NT systems may be configured with weak account lockout policies. This allows an attacker to repeatedly guess user passwords without the account being automatically disabled or locked. If exploited, this could lead to unauthorized access to corporate data or system resources through successful brute-force attacks.
Technical details
This vulnerability stems from insecure default or manual configurations of the Windows NT account lockout policy. Specifically, it involves settings where the 'lockout threshold' (number of failed attempts) is too high or disabled, and the 'lockout duration' is too short. An unauthenticated attacker with network access to the authentication interface can perform automated brute-force or dictionary attacks against user accounts. Because the policy does not sufficiently throttle or block these attempts, the probability of a successful credential compromise is significantly increased. Administrators should review and harden account lockout policies to ensure accounts are disabled after a reasonable number of failed attempts.
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed