FREE Registration is required
Overview:
This patch eliminates a security vulnerability in a component that ships with Microsoft Office 2000, Windows 2000, and Windows Me. The vulnerability could, under certain circumstances, allow a malicious user to obtain cryptographically protected logon credentials from another user when requesting an Office document from a Web server.The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via Web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to an implementation flaw, WEC does not respect the IE Security settings regarding when NTLM authentication will be performed. Instead, WEC will perform NTLM authentication with any server that requests it. If a user established a session with a malicious user's Web site, either by browsing to the site or by opening an HTML mail that initiated a session with it, an application on the site could capture the user's NTLM credentials. The malicious user could then use an offline brute-force attack to derive the password or, with specialized tools, could submit a variant of these credentials in an attempt to access protected resources.The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, allow a malicious user to gain control of another user's computer or to gain access to resources to which that user was authorized access. In order to leverage the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely logon to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices were followed, they would prevent an attacker from using the credentials to logon to the target system.Frequently asked questions regarding this vulnerability can be found here.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Software | Size: | 304 KB |
| Date: | Jan 2001 | Version: | MS01-001 |
| License: | Free | ||
| Platform: | Windows | ||
| System Req: | Windows Me, Office 2000 NOT installed |
People who downloaded this item also downloaded
![]() |
Windows 2000 High Encryption Pack 5.00.2150.1 (Windows) |
Top results from Encryption Software
![]() |
Brightfilter Parental Control 2009 2.1.0.1 (Windows) |
![]() |
RoboForm 6.9.97 (Windows) |
![]() |
Parent Cyber Alert 4.30 (Windows) |
![]() |
USB Secure 1.2.5 (Windows) |
![]() |
AutoKrypt 8.12 (Windows) |
White Papers, Webcasts, and Resources
- Microsoft Online Services Business Value MicrosoftGain access to rich communication, collaboration, and productivity applications from anywhere with subscription-based Microsoft Online Services.
- Is your network ready for IP Telephony? ShoreTelGet straight facts about IP telephony planning and deployment, including the critical importance of starting with a thorough network assessment.
- Orthopedic Center to Grow 30 Percent and Boost Productivity With Online Services MicrosoftRead how one healthcare provider dramatically lowered costs--saving over $35,000 annually on licensing fees alone--using Microsoft Online Services.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- Save time with automated shipping solutions
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Visit the UPS Business Essentials Guide
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
- The more you simplify, the more you save
-
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer>>
-
-
Smart Tech
Expert advice on innovations in healthcare and the green technologies that make it happen.
Find out more
-
Smart Business
Discussion and advice on management issues that revolve around making your world smarter and more useful.
More Smart Advice
-
Smart People
The best and worst moves in the management and strategy trenches.
Learn More






