Microsoft Windows NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability (CVE-2000-1200)
Publish Date: 21 de июля de 2015
Severity: : Medium
Advisory Date: 21 de июля de 2015
DESCRIPTION
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1005448