积极预防 及时发现
快速响应 力保恢复
Windows NT 允许远程攻击者通过使用空会话以及LsaQueryInformationPoli...
发布时间:2001-08-31 信息来源:管理员

CNCVE编号:CNCVE-20001200 CVE编号:CAN-2000-1200 安全级别:中 漏洞中文描述: Windows NT 允许远程攻击者通过使用空会话以及LsaQueryInformationPolicy 策略函数,并进一步使用域安全标识符(SID,Security Identifier) 来得到域中所有用户列表。 漏洞英文描述: Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. 漏洞参考: Reference: BUGTRAQ:20000201 Windows NT and account list leak ! A new SID usage Reference: URL:http://www.securityfocus.com/archive/1/44430 Reference: XF:nt-lsa-domain-sid(4015) Reference: URL:http://xforce.iss.net/static/4015.php Reference: BID:959 系统类型: Win2000/NT 漏洞类型:权限有效性检查错误