As a security vulnerability, it's interesting but, as they stated, low-severity.<p>If you have physical access and a local user, it's much easier to use any Linux boot CD and one of the myriad "password recovery" systems.<p>I used Petter N Hagen's <a href="http://pogostick.net/~pnh/ntpasswd/" rel="nofollow">http://pogostick.net/~pnh/ntpasswd/</a><p>back in my tech support days (several years ago).<p>The current tech support guy swears by Hiren's BootCD<p><a href="http://www.hiren.info/pages/bootcd" rel="nofollow">http://www.hiren.info/pages/bootcd</a>