Microsoft Web Extender Client May Expose NTLM Credentials

The Web Extender Client (WEC) might send clients' NT LAN Manager (NTLM) credentials to a remote server if requested to do so, regardless of the Microsoft Internet Explorer (IE) security settings.

ITPro Today

January 10, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedJanuary 11, 2001,by Microsoft

VERSIONS AFFECTED

  • Microsoft Office 2000

  • Microsoft Windows Me

  • Microsoft Windows 2000

DESCRIPTION

TheWeb Extender Client (WEC) might send clients' NT LAN Manager (NTLM) credentialsto a remote server if requested to do so, regardless of the Microsoft InternetExplorer (IE) security settings.

VENDORRESPONSE

Microsofthas released bulletin MS00-0101,patches, FAQ# FQ00-0101,and will make article Q282132 available online soon

CREDIT
Discovered by DavidLitchfield,@stake, Inc.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like