Security News Microsoft Account Credentials Leak vulnerability

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
What would you say if I told you that an almost two decade old vulnerability in Windows may leak your Microsoft Account credentials when you visit a website, read an email, or use VPN over IPSec?

A bug, that goes all the way back to Windows 95 is causing major issues on Windows 8 and Windows 10.

Basically, what happens is the following: Microsoft Edge, Internet Explorer, Outlook and other Microsoft products allow connections to local network shares. What the default settings don't prevent on top of that is connections to remote shares.

An attacker could exploit this by creating a website or email with an embedded image or other content that is been loaded from a network share.

Microsoft products like Edge, Outlook or Internet Explorer try to load the network share resource, and send the active user's Windows login credentials, username and password to that network share.

The username is submitted in plaintext, the password as a NTLMv2 hash.

Microsoft Account Credentials Leak vulnerability
microsoft-account-leak.png


Full Article. Microsoft Account Credentials Leak vulnerability - gHacks Tech News
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Security Warning:

"An issue in all Windows systems might leak the user's Windows login and password information. This is especially critical if the user is using a Microsoft account because this is linked to a number of other services the user may be using.

While this test requires you to click a button, really nothing more than visiting a web page with Internet Explorer or Edge is required to leak login credentials. Read our post for the details.

CAUTION: If you press the button below, this website will test whether you are vulnerable to an attack that possibly leaks your Windows and/or Microsoft Live login credentials. DOING THIS TEST MIGHT SEND YOUR WINDOWS AND MICROSOFT LIVE USERNAME AND PASSWORD HASH OVER THE INTERNET IN PLAIN TEXT. If that is the case, you should change it immediately afterwards."​

It is strongly recommended that you change your password immediately after the use of the site above.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top