First published: Thu Oct 06 2005(Updated: )
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3174 is considered to be of medium severity as it allows unauthorized domain logins with expired passwords.
To fix CVE-2005-3174, install Update Rollup 1 for Windows 2000 Service Pack 4.
CVE-2005-3174 affects Microsoft Windows 2000 before Update Rollup 1 for Service Pack 4.
CVE-2005-3174 allows users to bypass password expiration policies, posing a security risk to the domain.
A possible workaround for CVE-2005-3174 is to enforce stricter password policies or disable FQDN login for accounts.