The password check performed by MBSA may take a long time, depending on the number of user accounts on the computer. The password check enumerates all user accounts on the target computer and performs limited password change attempts using common password pitfalls, such as a password that is the same as the user name. To limit the impact of weak password checks on domain controllers, MBSA does not perform a full set of weak password checks against domain controllers.
Source: http://msdn.microsoft.com/en-us/library/ff647642.aspx