Skip to main content

Legacy Microsoft Account bug could cause issues for Windows 10 users

windows 10 insider preview 14955 outlook mail calendar narrator upgrade
Bill Roberson/Digital Trends
On the surface, Windows 10 looks almost nothing like its predecessor, Windows 95. However, there’s now word that the current version of Microsoft’s flagship OS might still possess a potentially ruinous security issue that’s more than a decade old.

Windows 8 and Windows 10 users could run afoul of this legacy bug as they enter their Microsoft Account credentials, according to a report from WinBeta. The issue is that services including Microsoft Edge, Internet Explorer, and Outlook allow connections to local network shares — but default settings don’t prevent connections to remote shares.

This could be exploited through the creation of a website or a scam email that uses content loaded from a network share. Microsoft’s web browsers and email clients would try load the network share resource, and in doing so, send the active user’s login credentials to that network share.

The report detailing this issue states that in this eventuality, usernames would be submitted in plain text, while the password would be hashed using the NTLMv2 protocol.

This problem was never such a threat in earlier versions of Windows, because users would log into their system with a local username and password. However, since Windows 8 and Windows 10 users log in with their Microsoft Account, there’s far more potential for this gap in security to be exploited.

The research team responsible for these findings recommends that users either adopt third-party services in place of their Microsoft equivalents for the time being, or use a “host-based hardening” technique detailed in their report.

However, it seems likely that Microsoft will deliver a fix as soon as possible, now that the issue has been detailed in this manner. The company just launched its much-hyped Windows 10 Anniversary Update on August 2, so now would be a good time to demonstrate an efficient response to security concerns such as this.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Windows 11 tips and tricks: 8 hidden settings you need to try
Windows 11 on a tablet.

Windows 11 has been around for quite a while now. The operating system isn't as new as when it first came out in 2021, but many people are still updating it for the first time from Windows 10. Yet whether you're new to Windows 11 or have been using it since launch, there are a few things that you still might want to tweak to get a better experience. Microsoft doesn't have all these settings upfront, but we're here to surface them for you.
Move the Taskbar and Start Menu to the left

One of the biggest differences between Windows 10 and Windows 11 is the location of the Taskbar and Start Menu. On Windows 10, the Taskbar and Start Menu are positioned to the left of the screen. Windows 11, though, changes that by moving both to the center. If this annoys you, then you can easily change it back.

Read more
Microsoft finds a sneaky way to slip more ads into Windows
The new windows 11 start menu.

Microsoft is currently testing a new way to showcase ads on the Windows 11 Start Menu, and it's meant to encourage users to download more applications.

The brand has used the top of the Windows start menu as an area to showcase general ads in the past, and it was not well-received by system users. However, it is now experimenting with putting what it calls “app promotions” at the bottom of the start menu area, according to Windows Central.

Read more
Microsoft announces a new threat to push people to Windows 11
Windows 11 and Windows 10 operating system logos are displayed on laptop screens.

Microsoft is sharing more details of its plans to transition customers still using Windows 10 from a free offering to a paid structure if they wish to continue receiving security updates.

The company is phasing out the legacy operating system, which will reach its end-of-life support on October 14, 2025. After this, Microsoft will begin charging enterprise users a monthly fee for Extended Security Updates (ESU). Businesses must purchase an ESU license for all Windows 10 devices in order to maintain security support beyond the cutoff date.

Read more