Microsoft network client: Send unencrypted password to third-party SMB servers

Information

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

If this security setting is enabled, the Server Message Block (SMB) redirector is allowed to send plaintext passwords to non-Microsoft SMB servers that do not support password encryption during authentication.

Sending unencrypted passwords is a security risk.

Default: Disabled.

Solution

Policy Path: Security Options
Policy Setting Name: Microsoft network client: Send unencrypted password to third-party SMB servers

See Also

https://blogs.technet.microsoft.com/secguide/2018/04/30/security-baseline-for-windows-10-april-2018-update-v1803-final/

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-5, CSCv6|13

Plugin: Windows

Control ID: cf71d76dbf53a69e6f8d6a588cb40ed7f7e9bf1b7de9fcf206beb830bb8f409a