Skip to main content

Legacy Microsoft Account bug could cause issues for Windows 10 users

windows 10 insider preview 14955 outlook mail calendar narrator upgrade
Bill Roberson/Digital Trends
On the surface, Windows 10 looks almost nothing like its predecessor, Windows 95. However, there’s now word that the current version of Microsoft’s flagship OS might still possess a potentially ruinous security issue that’s more than a decade old.

Windows 8 and Windows 10 users could run afoul of this legacy bug as they enter their Microsoft Account credentials, according to a report from WinBeta. The issue is that services including Microsoft Edge, Internet Explorer, and Outlook allow connections to local network shares — but default settings don’t prevent connections to remote shares.

This could be exploited through the creation of a website or a scam email that uses content loaded from a network share. Microsoft’s web browsers and email clients would try load the network share resource, and in doing so, send the active user’s login credentials to that network share.

The report detailing this issue states that in this eventuality, usernames would be submitted in plain text, while the password would be hashed using the NTLMv2 protocol.

This problem was never such a threat in earlier versions of Windows, because users would log into their system with a local username and password. However, since Windows 8 and Windows 10 users log in with their Microsoft Account, there’s far more potential for this gap in security to be exploited.

The research team responsible for these findings recommends that users either adopt third-party services in place of their Microsoft equivalents for the time being, or use a “host-based hardening” technique detailed in their report.

However, it seems likely that Microsoft will deliver a fix as soon as possible, now that the issue has been detailed in this manner. The company just launched its much-hyped Windows 10 Anniversary Update on August 2, so now would be a good time to demonstrate an efficient response to security concerns such as this.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Here’s proof that Snapdragon X Elite laptops can play hit games without issue
A laptop and a camera on a table with a Qualcomm logo on the screen.

Windows laptops with Qualcomm's ARM-based Snapdragon X Elite chip are set to come this summer, but we're already getting a preview of how good the devices will be for gaming. A recent video surfaced online showing how one of the most popular PC games, Baldur's Gate 3, can run on a Qualcomm reference laptop with the chip -- and it does look to be pretty impressive.

As shared by Devin Arthur on X, Qualcomm ran this game on a sample laptop at 1080p resolution. The demo was done in a public setting, and it's not clear what else was changed beyond that, but it does appear stable, with little to no lag.

Read more
Surface Pro 10 and Surface Laptop 6 have arrived — with a catch
A top down view of the Surface Laptop 6, highlighting the Copilot button.

Microsoft has taken the wraps off some new Surface devices today. Though the latest Surface Pro 10 for Buisness and Surface Laptop 6 for Buisness are only for commercial users, the new products preview consumer versions that are expected to be coming later this year.

While not majorly redesigned, the devices pack a promising jump in performance under the hood thanks to the Intel Core Ultra CPU, as well as some features enterprise users will surely appreciate. AI is also a big focus in the form of Copilot.
Surface Laptop 6 for Business

Read more
Windows 11 24H2 or Windows 12? Here’s what’s coming soon
A laptop running Windows 11.

Windows 11 is more than a few years old and it is getting feature drops called "moments" every so often, as well as yearly updates. But what about the whole new Windows release that will come after Windows 11?

Earlier leaks from Intel and Qualcomm made mention of Windows 12, leading some to believe that Windows 12 might be in development at Microsoft and could come in 2024.

Read more