Microsoft Windows NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability (CVE-2000-1200)

  Severity: MEDIUM
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005448

Featured Stories