![]() |
New Microsoft Articles and Security Bulletins #2 |
Cached security credentials, which include the password, are stored in the registry and protected by ACLs whose default values authorize only local administrators and the user to access them. Windows NT 4.0 Service Pack 4 also provides the ability to strongly encrypts the password data stored in the registry using the SYSKEY feature.
While there are no reports of customers being adversely affected by this vulnerability, Microsoft is proactively releasing a patch that restores correct functionality to the password caching function. The patch should be applied to all machines that are used as RAS or RRAS clients. It is important to note that RRAS servers also can be used as RRAS clients, and any machines used in such a capacity should have the patch applied as well.
Affected Software Versions
==========================
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Server 4.0, Enterprise Edition
What Microsoft is Doing
=======================
Microsoft has released patches that fix the problem identified. The
patches are available for download from the sites listed below in What
Customers Should Do.
Microsoft also has sent this security bulletin to customers subscribing to the Microsoft Product Security Notification Service.
See http://www.microsoft.com/security/services/bulletin.asp for more information about this free customer service.
Microsoft has published the following Knowledge Base (KB) article on this issue: - Microsoft Knowledge Base (KB) article Q230681,
RAS Credentials Saved when "Save Password" Option Unchecked,
http://support.microsoft.com/support/kb/articles/q230/6/81.asp
- Microsoft Knowledge Base (KB) article Q233303,
RRAS Credentials Saved when "Save Password" Option Unchecked,
http://support.microsoft.com/support/kb/articles/q233/3/03.asp
Web Style and Custom Options Unavailable on General Tab (Q217373)
http://support.microsoft.com/support/kb/articles/q217/3/73.asp
Causing Windows 98 to Release DHCP Lease Information at Shutdown
(Q217035)
http://support.microsoft.com/support/kb/articles/q217/0/35.asp
"Unable to Load Product Specific DLL" Starting Backup (Q216912)
http://support.microsoft.com/support/kb/articles/q216/9/12.asp
Computer Hangs After 49.7 Days (Q216641)
http://support.microsoft.com/support/kb/articles/q216/6/41.asp
Reconnecting to RAS Server Does Not Require Logon (Q216616)
http://support.microsoft.com/support/kb/articles/q216/6/16.asp
Unable to View Secure Web Sites Using America Online (Q216592)
http://support.microsoft.com/support/kb/articles/q216/5/92.asp
Changes to Your Computer Not Saved After Incorrect Shut Down (Q216302)
http://support.microsoft.com/support/kb/articles/q216/3/02.asp
Notepad Font Formatting Is Not Visible in Other Text Editors (Q216380)
http://support.microsoft.com/support/kb/articles/q216/3/80.asp
Intel Pentium III CPU Identified as Intel Pentium II CPU (Q216204)
http://support.microsoft.com/support/kb/articles/q216/2/04.asp
Unknown Devices in Device Manager After Upgrading to Windows 98 (Q216137)
http://support.microsoft.com/support/kb/articles/q216/1/37.asp
Task Scheduler Service Does Not Start (Q215937)
http://support.microsoft.com/support/kb/articles/q215/9/37.asp
Unable to Connect Three Levels Higher in a Domain (Q215422)
http://support.microsoft.com/support/kb/articles/q215/4/22.asp
Problems Upgrading Samsung Sens 810 Computer to Windows 98 (Q215356)
http://support.microsoft.com/support/kb/articles/q215/3/56.asp
"File Is Too Large to Open" Message in Notepad (Q215340)
http://support.microsoft.com/support/kb/articles/q215/3/40.asp
Availability of the OLE Automation Fix for Windows 95/98 (Q214845)
http://support.microsoft.com/support/kb/articles/q214/8/45.asp
When You Point to a Menu the Submenu May Not Appear (Q214831)
http://support.microsoft.com/support/kb/articles/q214/8/31.asp
Error Message: Error Downloading Component (Q214786)
http://support.microsoft.com/support/kb/articles/q214/7/86.asp
Modem Detected on Wrong COM Port on Acer Aspire (Q213166)
http://support.microsoft.com/support/kb/articles/q213/1/66.asp
Drive A Present Even Though it Is Not Physically Connected (Q205942)
http://support.microsoft.com/support/kb/articles/q205/9/42.asp
Hard Disk No Longer Available After Uninstalling Windows 98 (Q205400)
http://support.microsoft.com/support/kb/articles/q205/4/00.asp
No Message When Cookie Is Not Saved on Your Computer (Q201549)
http://support.microsoft.com/support/kb/articles/q201/5/49.asp
CH Products F16 CombatStick Loses Calibration in Windows 98 (Q201464)
http://support.microsoft.com/support/kb/articles/q201/4/64.asp
Philips Monitor Model Number Not Listed in Windows 95/98 (Q200136)
http://support.microsoft.com/support/kb/articles/q200/1/36.asp
"Color 2" Box Unavailable When Choosing Active Title Bar Colors (Q199936)
http://support.microsoft.com/support/kb/articles/q199/9/36.asp
How to Disable Advanced Power Management for PC Card Modems (Q199209)
http://support.microsoft.com/support/kb/articles/q199/2/09.asp
Unable to See or Use the Taskbar (Q199161)
http://support.microsoft.com/support/kb/articles/q199/1/61.asp
Err Msg: The Wave Task Manager (NSPMM.DLL) Is Not Available (Q199097)
http://support.microsoft.com/support/kb/articles/q199/0/97.asp
MS-DOS-Based Programs Do Not Play Beeps Through PC Speaker (Q199030)
http://support.microsoft.com/support/kb/articles/q199/0/30.asp
Start Menu Policies May Not Work Using the Shell.adm File (Q199013)
http://support.microsoft.com/support/kb/articles/q199/0/13.asp
DirectX Diagnostic Tool Reports Old or Beta Files (Q198877)
http://support.microsoft.com/support/kb/articles/q198/8/77.asp
Fatal Exception in CDVSD Starting Windows 98 (Q197004)
http://support.microsoft.com/support/kb/articles/q197/0/04.asp
Computer Stops Responding When Creating a Remote Access Session (Q194178)
http://support.microsoft.com/support/kb/articles/q194/1/78.asp
Err Msg: Synchronization Manager Cannot Find Critical... (Q216681)
http://support.microsoft.com/support/kb/articles/q216/6/81.asp
Appointments in Australian Cities Are Synchronized Incorrectly (Q216456)
http://support.microsoft.com/support/kb/articles/q216/4/56.asp
Err Msg: The Command Is Not Available. See the Program... (Q216314)
http://support.microsoft.com/support/kb/articles/q216/3/14.asp
Folders Named "New Folder" Appear in Voice Recorder (Q199498)
http://support.microsoft.com/support/kb/articles/q199/4/98.asp
Images Lost After Saving Word 97 File in Pocket Word Format (Q201796)
http://support.microsoft.com/support/kb/articles/q201/7/96.asp
InkWriter Does Not Print Fonts Larger Than 11 Point (Q199398)
http://support.microsoft.com/support/kb/articles/q199/3/98.asp
Pocket Outlook Err Msg: <Unsupported Message Type Removed> (Q233304)
http://support.microsoft.com/support/kb/articles/q233/3/04.asp
How to Check MSN E-mail on Windows CE HPC Device (Q231404)
http://support.microsoft.com/support/kb/articles/q231/4/04.asp
Err Msg: The Security Certificate for This Site Has Either... (Q222931)
http://support.microsoft.com/support/kb/articles/q222/9/31.asp
No Error Message When Windows CE Synchronization Does Not Work (Q222158)
http://support.microsoft.com/support/kb/articles/q222/1/58.asp
Windows CE Cannot Make IMAP4 Connection (Q221217)
http://support.microsoft.com/support/kb/articles/q221/2/17.asp
Error Message: Memory Running Critically Low
http://support.microsoft.com/support/kb/articles/q201/1/50.asp
OFF2000: Setup Cannot Find a Qualifying Product During CD2 Setup (Q231664)
http://support.microsoft.com/support/kb/articles/Q231/6/64.asp
Q238445 XL97: Potential Security Issue with Microsoft Access ODBC
Driver
http://support.microsoft.com/support/kb/articles/q238/4/45.asp
Q217027 OFF95: How to Download and Install the Year 2000 Update
http://support.microsoft.com/support/kb/articles/Q217/0/27.asp
Q234688 OFF2000: Web Publishing Wizard Files Cannot Be Found During
Setup
http://support.microsoft.com/support/kb/articles/Q234/6/88.asp
Q176943 XL97: Year 2000 Wizards for Microsoft Excel 97
http://support.microsoft.com/support/kb/articles/q176/9/43.asp
Q238445 XL97: Potential Security Issue with Microsoft Access ODBC
Driver
http://support.microsoft.com/support/kb/articles/q238/4/45.asp
Q220980 XL97: Not All Workbooks Print When Printing from Windows
Explorer
http://support.microsoft.com/support/kb/articles/q220/9/80.asp
Q222844 XL97: #REF! Error Recalculating Worksheet with Defined Name
http://support.microsoft.com/support/kb/articles/q222/8/44.asp
Q229816 XL97: Errors Saving to an Earlier File Format When Transition
Formula Evaluation Is Enabled
http://support.microsoft.com/support/kb/articles/q229/8/16.asp
Q238570 XL97: "Out of Virtual Memory" Opening Many Workbooks with
ActiveX or OCX Controls
http://support.microsoft.com/support/kb/articles/q238/5/70.asp
Q212740 XL2000: Text Box Border Appears Jagged in Browser
http://support.microsoft.com/support/kb/articles/q212/7/40.asp
Q214391 XL2000: How Microsoft Excel Works with Two-Digit Year Numbers
http://support.microsoft.com/support/kb/articles/q214/3/91.asp
Q221493 XL2000: Code Module May Be Missing After Opening and Saving
Workbook as Web Page
http://support.microsoft.com/support/kb/articles/q221/4/93.asp
Q221500 XL2000: Page Setup Properties for Embedded Chart on Worksheet
Lost After Saving as Web Page
http://support.microsoft.com/support/kb/articles/q221/5/00.asp
Q229006 XL2000: Colors in HTML File Don't Appear as Expected When
Opening Page in Excel
http://support.microsoft.com/support/kb/articles/q229/0/06.asp
Q234132 SBFM2000: Tax Savings from Depreciation Appears for Non-Depreciated
Asset
http://support.microsoft.com/support/kb/articles/q234/1/32.asp
Q235069 XL2000: Unsigned Macros May Be Trusted When Macro Security
Setting Is High
http://support.microsoft.com/support/kb/articles/q235/0/69.asp
Q235093 XL2000: Web Page Created in Office 2000 Cannot Be Opened
on the Macintosh
http://support.microsoft.com/support/kb/articles/q235/0/93.asp
Q235429 XL2000: Multiple-Level Category Labels Displayed Differently
in Excel 2000
http://support.microsoft.com/support/kb/articles/q235/4/29.asp
Q235520 XL2000: "Cannot quit EXCEL.EXE" and Can't Log Off from Windows
NT If Excel File Open in Internet Explorer
http://support.microsoft.com/support/kb/articles/q235/5/20.asp
Q236298 XL2000: Date Labels on X-Axis of XY (Scatter) Chart Distorted
When Rotated 90 Degrees
http://support.microsoft.com/support/kb/articles/q236/2/98.asp
Q236331 XL2000: Supporting Data for the Initial View of Your PivotTable
May Be Visible to Users
http://support.microsoft.com/support/kb/articles/q236/3/31.asp
Q236990 XL2000: Parameter Query Does Not Refresh Automatically
http://support.microsoft.com/support/kb/articles/q236/9/90.asp
Q238482 XL2000: Cell Ranges in Aggregate Formulas May Change Unexpectedly
http://support.microsoft.com/support/kb/articles/q238/4/82.asp
Q130494 XL2000: "This File Has Been Locked" Error Saving Shared Workbook
http://support.microsoft.com/support/kb/articles/q130/4/94.asp
Q179871 XL2000: Methods for Recovering Data from Damaged Workbooks
http://support.microsoft.com/support/kb/articles/q179/8/71.asp
Q179886 XL2000: List of Supported File Formats in Microsoft Excel
2000
http://support.microsoft.com/support/kb/articles/q179/8/86.asp
Q181212 XL2000: Performing a Lookup with Unsorted Data in Excel
http://support.microsoft.com/support/kb/articles/q181/2/12.asp
Q181298 XL2000: How to Convert Text to Number
http://support.microsoft.com/support/kb/articles/q181/2/98.asp
Q181918 XL2000: Number Formatting Affects Perceived Precision
http://support.microsoft.com/support/kb/articles/q181/9/18.asp
Q210701 XL2000: Saving File in Excel 97 Loses PivotTable Field Layout
Options
http://support.microsoft.com/support/kb/articles/q210/7/01.asp
Q211552 XL2000: Attached Toolbar Is Not Saved in 5.0/95 File Format
http://support.microsoft.com/support/kb/articles/q211/5/52.asp
Q211591 XL2000: Text Contained in AutoShapes Does Not Rotate
http://support.microsoft.com/support/kb/articles/q211/5/91.asp
Q213624 XL2000: How to Create an Auto_Open Macro to Show Data Form
Dialog Box
http://support.microsoft.com/support/kb/articles/q213/6/24.asp
Q213955 XL2000: Error Message "PivotTable field name is not valid..."
When Refreshing, Creating PivotTable Report
http://support.microsoft.com/support/kb/articles/q213/9/55.asp
Q215904 XL2000: Changing a PivotChart Removes Series Formatting
http://support.microsoft.com/support/kb/articles/q215/9/04.asp
Q215927 XL2000: Currency in Cell Formatted Differently Than Expected
http://support.microsoft.com/support/kb/articles/q215/9/27.asp
Q221492 XL2000: Publishing Cells with Spilled Text Creates Merged
Cells
http://support.microsoft.com/support/kb/articles/q221/4/92.asp
Q223428 XL2000: Error Message "There are no printers installed"
http://support.microsoft.com/support/kb/articles/q223/4/28.asp
Q230137 XL2000: Not All Workbooks Print When Printing from Windows
Explorer
http://support.microsoft.com/support/kb/articles/q230/1/37.asp
Q231045 XL2000: "Name cannot resemble a reference." Error When Changing
Reference Style Setting
http://support.microsoft.com/support/kb/articles/q231/0/45.asp
Q233073 XL2000: How to Prevent the Automatic Creation of Hyperlinks
http://support.microsoft.com/support/kb/articles/q233/0/73.asp
Q235099 XL2000: Custom Function May Return Different Result When
Opened as HTML File
http://support.microsoft.com/support/kb/articles/q235/0/99.asp
Q235303 XL2000: Errors Activating Microsoft Map Created in an Earlier
Version of Excel
http://support.microsoft.com/support/kb/articles/q235/3/03.asp
Q236091 XL2000: "Cannot connect to the data source..." Error Refreshing
OLAP PivotTable
http://support.microsoft.com/support/kb/articles/q236/0/91.asp
Q223153 OL98: (CW) Invalid Page Fault After Installing Internet Explorer
5
http://support.microsoft.com/support/kb/articles/q223/1/53.asp
Q192478 OL2000: New Outlook Today Customization Options
http://support.microsoft.com/support/kb/articles/q192/4/78.asp
Q236081 OL2000: Finding Information About Customizing Outlook Today
http://support.microsoft.com/support/kb/articles/q236/0/81.asp
Q195558 OL2000: Spelling Checker Adds Extra Period to Abbreviations
http://support.microsoft.com/support/kb/articles/q195/5/58.asp
Q195559 OL2000: (CW) Mail Forwarded to Internet by Rule May Fail
http://support.microsoft.com/support/kb/articles/q195/5/59.asp
Q218344 OL2000: Symantec Fax Starter Edition Fails After Set Up
http://support.microsoft.com/support/kb/articles/q218/3/44.asp
Q222196 OL2000: Stationery Picker Unavailable When Using Word As
Your E-mail Editor
http://support.microsoft.com/support/kb/articles/q222/1/96.asp
Q222198 OL2000: Hyperlink Behavior with Different E-mail Formats
http://support.microsoft.com/support/kb/articles/q222/1/98.asp
Q223735 OL2000: Internet Free/Busy Information Not Updated
http://support.microsoft.com/support/kb/articles/q223/7/35.asp
Q223946 OL2000: Saving an HTML Message As an HTML File Removes Images
http://support.microsoft.com/support/kb/articles/q223/9/46.asp
Q223986 OL2000: (CW) Free/Busy Information Not Updated for Some Attendees
on Exchange Server
http://support.microsoft.com/support/kb/articles/q223/9/86.asp
Q232303 OL2000: How the Forms Cache Works
http://support.microsoft.com/support/kb/articles/q232/3/03.asp
Q218210 OL2000: (IMO) Multi-part Secured Messages May Not Be Reassembled
Correctly
http://support.microsoft.com/support/kb/articles/q218/2/10.asp
Support Highlights for Office 2000 are now available on the Personal Support Center.
Access 2000
http://support.microsoft.com/support/default.asp?PR=acc2000
Excel 2000
http://support.microsoft.com/support/default.asp?PR=xlw2K
Office 2000 (Setup and Common Issues)
http://support.microsoft.com/support/default.asp?PR=ofw2k
Outlook 2000
http://support.microsoft.com/support/default.asp?PR=out2K
PowerPoint 2000
http://support.microsoft.com/support/default.asp?PR=ppt2000
Word 2000
http://support.microsoft.com/support/default.asp?PR=wrd20
Q220780 OFF2000: Setup Error 2755 with Previous Office Version Installed
http://support.microsoft.com/support/kb/articles/q220/7/80.asp
Q228607 OFF2000: Office Assistant Reminder Stops Computer with Hauppauge
WinTV Full Screen
http://support.microsoft.com/support/kb/articles/q228/6/07.asp
Q236821 OFF2000: Error 2336 During Office 2000 Setup
http://support.microsoft.com/support/kb/articles/q236/8/21.asp
Q236905 OFF2000: How to Install Office 2000 on a Dual-Boot System
http://support.microsoft.com/support/kb/articles/q236/9/05.asp
Q237578 OFF2000: Internal Error 2381 Running Office Setup on Windows
NT
http://support.microsoft.com/support/kb/articles/q237/5/78.asp
Q237915 OFF2000: Windows Installer "Error 1324" When Running Setup
http://support.microsoft.com/support/kb/articles/q237/9/15.asp
Q237957 OFF2000: How to Use an Office 2000 Setup Log File to Troubleshoot
Setup Problems
http://support.microsoft.com/support/kb/articles/q237/9/57.asp
Q238122 OFF2000: Installing Office on Windows 95 and Windows 98 with
and Without Profiles
http://support.microsoft.com/support/kb/articles/q238/1/22.asp
Q235335 OFF2000: Error Message "Ie5wzd caused an exception in module
Msjava.dll" During Setup
http://support.microsoft.com/support/kb/articles/q235/3/35.asp
Q235662 OFF2000: Internal Error 2344 When Running Office 2000 Setup
http://support.microsoft.com/support/kb/articles/q235/6/62.asp
Q237381 MS Graph 2000: Characters Lost or Changed to All Caps When
Typed
http://support.microsoft.com/support/kb/articles/q237/3/81.asp
Q202946 OFF2000: Setup Command-Line Switches for Office 2000
http://support.microsoft.com/support/kb/articles/q202/9/46.asp
Q205499 OFF2000: Cannot Access Help Topic When Drive Not Available
http://support.microsoft.com/support/kb/articles/q205/4/99.asp
Q210391 OFF2000: Setup May Remove Older Components
http://support.microsoft.com/support/kb/articles/q210/3/91.asp
Q217221 OFF2000: Using SelfCert to Create a Digital Certificate for
VBA Projects
http://support.microsoft.com/support/kb/articles/q217/2/21.asp
Q217585 OFF2000: Not Enough Disk Space Message When Installing Office
http://support.microsoft.com/support/kb/articles/q217/5/85.asp
Q217623 OFF2000: Unable to Restart Registration Wizard
http://support.microsoft.com/support/kb/articles/q217/6/23.asp
Q217714 OFF2000: Setup Appears to Hang Followed by Internal Error
2336 or 2755
http://support.microsoft.com/support/kb/articles/q217/7/14.asp
Q217883 OFF2000: System Requirements for Office
http://support.microsoft.com/support/kb/articles/q217/8/83.asp
Q218853 OFF2000: Troubleshooting Office Kernel32.dll Errors Under
Windows 98
http://support.microsoft.com/support/kb/articles/q218/8/53.asp
Q218873 OFF2000: Troubleshooting Office Kernel32.dll Errors Under
Windows 95
http://support.microsoft.com/support/kb/articles/q218/8/73.asp
Q221354 OFF2000: "Problem Starting the Office Assistant" Error Running
Office Programs
http://support.microsoft.com/support/kb/articles/q221/3/54.asp
Q224095 OFF2000: Error Message "This application requires the Windows
Installer to run. Would you like to install this service now?"
http://support.microsoft.com/support/kb/articles/q224/0/95.asp
Q224099 OFF2000: Error Message "No procedure for creating files of
this type is registered with the shell."
http://support.microsoft.com/support/kb/articles/q224/0/99.asp