Skip to content

H3-2023-0030

Active Directory - User Password Not Required

Category SECURITY_MISCONFIGURATION
Base Score 4.3

Description

User objects within Active Directory have attributes that can be added/deleted/edited by a privileged user. The userAccountControl attribute has a PASSWD_NOTREQD flag that, if set, allows a User to not have a password. However, This does not mean the user actually has a blank password, just that is is possible.",

Impact

An authenticated user could discover an enabled user with the PASSWD_NOTREQD flag set and may be able to login as that user without a password.

References