CVE-2000-1217: Medium severity Microsoft Windows 2000 vulnerability
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
Affected Software
Event History
Frequently Asked Questions
Which systems are affected by this issue?
Microsoft Windows 2000 systems before Service Pack 2 are affected only when they are in a non-Windows 2000 domain, use NTLM authentication, and have credentials for an account cached locally.
What access does an attacker need to exploit it?
The attacker must be a local user on the affected Windows 2000 system. Exploitation relies on locally cached credentials and enables repeated login attempts without enforcement of the account lockout policy.
What is the practical impact of exploitation?
A local attacker can bypass account lockout policies and make an unlimited number of login attempts against a cached account, increasing the opportunity to guess that account's credentials.