- Quick specs
- Price: Free
- Operating system: Windows 2000
- Date added: November 28, 2000
- Total Downloads: 9,710
- Downloads last week: 2
- See full specifications
- Average user rating: stars out of 4 votes
See all user reviews
Publisher's description
From Microsoft :This patch eliminates a security vulnerability in Microsoft Windows 2000. The vulnerability could allow a malicious user to use repeated attempts to guess an account password even if the domain administrator had set an account lockout policy.
A flaw in the way that NTLM authentication operates in Windows 2000 could allow a domain account lockout policy to be bypassed on a local Windows 2000 machine, even if the domain administrator had set such a policy. The ability of a malicious user to avoid the domain account lockout policy could increase the threat from a brute force password-guessing attack.
This vulnerability only affects Windows 2000 machines that are members of non-Windows 2000 domains. In addition, the vulnerability only affects domain user accounts that have previously logged into the target machine and already have cached credentials established on that machine. If a domain account lockout policy is in place and an attacker attempts a brute force password-guessing attack, the domain user account will be locked out as expected at the domain controller. However, if the attacker is able find the correct password, the local Windows 2000 machine will log the attacker on using cached credentials in violation of the account lockout policy. Although the attacker would be able to log on to the local machine, he or she would not be able to authenticate to the domain or gain access to resources on other machines in the domain.
CNET Editor's Note: Windows 2000 Gold is not affected by this vulnerability. This patch will be included in Windows 2000 Service Pack 2. Domain Account Lockout vulnerability FAQ.
More popular Encryption Software downloads
- 52,623 downloads 1. RoboForm
- 27,875 downloads 2. Hotspot Shield
- 26,862 downloads 3. Computer Use Reporter
- 8,814 downloads 4. Easy File Encryption
- 8,095 downloads 5. Easy Private Disk
- See all Encryption Software downloads
User reviews
- Average user rating: 0 stars Not yet available
- My rating: 0 stars Write review
-
Showing 1 of 1 user reviewSee 1 user review
This software version | All versions -
Version: Windows 2000 Domain Account Lockout Vulnerability Patch MS00-089
Summary: Well I was happy there was a patch. But became nearly crazy because it did not work. The patch sucks.
- See 1 user review Write review
Submit your review
- See more CNET content tagged:
- Microsoft Windows 2000,
- attacker,
- domain,
- malicious user,
- policy

