Microsoft Product Support Services   All Products  |   Support  |   Search  | Home
  Support Home  |   Find a Solution  |   Request Support  |   Custom Support  |

Token Handle Leak in Lsass When Using Basic Authentication

The information in this article applies to:
  • Microsoft Windows versions 2000, 2000 SP1 Server
  • Microsoft Windows versions 2000, 2000 SP1 Advanced Server


When you are using an active server page (ASP) that creates a remote component services component by using local user accounts with basic authentication, there may be a token handle leak in Lsass.exe.


A supported fix is now available from Microsoft, but it is only intended to correct the problem described in this article and should be applied only to systems experiencing this specific problem. This fix may receive additional testing at a later time, to further ensure product quality. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Windows 2000 service pack that contains this fix.

To resolve this problem immediately, download the fix as instructed below or contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information on support costs, please go to the following address on the World Wide Web:
NOTE: In special cases, charges that are normally incurred for support calls may be canceled, if a Microsoft Support Professional determines that a specific update will resolve your problem. Normal support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

The following files are available for download from the Microsoft Download Center:
English (US):
[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_en.exe now

Chinese (Simplified):
[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_cn.exe now

Chinese (Traditional):
[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_tw.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_cs.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_nl.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_fr.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_de.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_hu.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_it.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_ja.exe now

Japanese (NEC):
[GRAPHIC: Download]Download Q291340_w2k_sp3_nec98_ja.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_ko.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_pl.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_pt.exe now

Portuguese (Brazil):
[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_br.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_ru.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_es.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_sv.exe now

[GRAPHIC: Download]Download Q291340_w2k_sp3_x86_tr.exe now
For additional information about how to download Microsoft Support files, click the article number below to view the article in the Microsoft Knowledge Base:
Q119591 How to Obtain Microsoft Support Files from Online Services
Microsoft used the most current virus detection software available on the date of posting to scan this file for viruses. Once posted, the file is housed on secure servers that prevent any unauthorized changes to the file.

The English version of this fix should have the following file attributes or later:
File name Size Date Time Version
Advapi32.dll 351,504 3/8/2001 2:09 PM 5.00.2195.3320
Kdcsvc.dll 141,584 3/8/2001 2:09 PM 5.00.2195.3300
Kerberos.dll 207,920 2/23/2001 2:55 PM 5.00.2195.3300
Ksecdd.sys 69,456 1/26/2001 7:51 PM 5.00.2195.3194
Lsasrv.dll 495,888 3/8/2001 2:09 PM 5.00.2195.3345
Lsass.exe 33,552 3/8/2001 2:07 PM 5.00.2195.3345
Ntdsa.dll 908,048 3/8/2001 2:09 PM 5.00.2195.3277
Samsrv.dll 381,712 3/8/2001 2:09 PM 5.00.2195.3327


Microsoft has confirmed this to be a problem in the Microsoft products listed at the beginning of this article.


For additional information about how to install Windows 2000 and Windows 2000 hotfixes at the same time, click the article number below to view the article in the Microsoft Knowledge Base:

Q249149 Installing Microsoft Windows 2000 and Windows 2000 Hotfixes

Additional query words:

Keywords : kbWin2000PreSP3Fix
Issue type : kbbug
Technology : kbwin2000AdvServSearch kbwin2000Ssearch kbwin2000Search kbwin2000ProSearch

Last Reviewed: March 15, 2001
© 2001 Microsoft Corporation. All rights reserved. Terms of Use.

Article ID: Q291340

Last Reviewed:
March 15, 2001

Send to a friend

Provided by
Microsoft Product Support Services

Did the information in this article help answer your question?

Did not apply

Please provide additional comments about this information.
(255 character max)