Configuration file with Windows account password is world readable.
vulners.com/securityvulns/securityvulns:doc:9840