Aorato created a proof-of-concept attack in which it was able to change a person’s network password. The problem stems from Active Directory’s backward compatibility with an authentication protocol called NTLM. The new password can then be used to access other services, such as remote desktop protocol (RDP) Security experts agreed that the problem is not a major risk for businesses. Microsoft says it has not shown anything new; the company says the flaw is a well-known limitation in the Kerberos Network Authentication Service standard.”]