Microsoft's widespread network access software has a critical design flaw, according to an Israeli security firm, but Microsoft says it has been aware of the issue for a long time and has implemented necessary security measures.
Aorato used public information to create a proof-of-concept attack that shows how an attacker can change password , potentially allowing them access to other sensitive systems, said Tal Be'ery, vice president of research.
“The devastating consequences we’re talking about — that an attacker could change the password — are certainly not known,” Be’ery said in a phone interview Tuesday. About 95 percent of Fortune 500 companies use Active Directory, making the problem “extremely critical,” Aorato wrote in her blog.

