Windows NT gina flaw allows some clipboard text to be revealed

Risk Level: Low risk vulnerability  Low

Check or Attack Name: NTginaPaste

Platforms: Windows NT: 3.5.1, Windows NT: 4.0, Windows NT: 4.0 SP4
Description:

A flaw has been found in Windows NT that allows anyone to view the contents of the first line from the clipboard of a user who has locked their terminal, by pasting into the console login username field.

Remedy:

Microsoft has released the Windows NT post-SP3 and post-SP4 gina-fix hotfix that remedies this problem and another similar vulnerability.

References:

Microsoft Knowledge Base Article Q214802, WinNT Lets You Paste Text into Unlock Workstation Dialog Box, http://support.microsoft.com/support/kb/articles/q214/8/02.asp


X-Force Logo
Know Your Risks