Windows NT Domain SID Enumeration Vulnerability

Windows NT Domain SID Enumeration Vulnerability

CVE-2000-1200 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

Learn more about our User Device Pen Test.