Category: Microsoft|Aug 3, 2016 | Author: Admin

Vulnerability affecting Microsoft Windows Version 8 and later

Share on

May cause the Windows Live login details being eksfiltrert

May cause the Windows Live login details being eksfiltrert

NorCERT will inform you about a vulnerability affecting Microsoft Windows
version 8 and later.
The vulnerability was discovered in 1997 [1] and is present in all Windows
systems since Windows 95 / NT, but gives only figures in the newer versions of
Microsoft Windows.

The vulnerability has previously led the username and email addresses have been leaked,
and hashed NTLMv2 password from the user's Microsoft Live account, provided that such
account is linked to its Windows client.

This vulnerability is a flaw where Edge / Internet Explorer / Outlook
allowed to be connected to external file directories (SMEs).
An attacker could exploit this vulnerability by sending a link to the external
Albums, and if the link is visited will login details related
user Live account will be sent in plain front.

This is an old vulnerability where it previously only been possible to
retrieve login details for local user, but as newer
versions of Windows using Microsoft Live account as the default login
these details could now be eksfiltrert.

A Microsoft Live account used for purposes including logging of the following
services:

  • OneDrive
  • Outlook
  • OfficeBing
  • Xbox Live
  • MSN
  • Skype

Recommended harm reduction measures are:

Do not use the Microsoft software that accesses the network sites over the Internet (such as Internet Explorer, Edge and Outlook)
Utilizing a strong login password that will be harder to crack
Do not use Microsoft Live account login on your local Windows machine

Sponsored Ads:

Comments:


This is how Huawei tricked its way into the US

Category: IT|May 2, 2024 | Author: Admin

Edge 125 arrives in Beta with sleeping tab improvements and other changes

Category: IT|May 1, 2024 | Author: Admin

Now the iPad opens

Category: Apple|Apr 30, 2024 | Author: Admin

Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin
more