NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
BID:959
Info
NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
| Bugtraq ID: | 959 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2000 12:00AM |
| Updated: | Feb 01 2000 12:00AM |
| Credit: | Posted to Bugtraq by Pascal Longpre <[email protected]> on February 1, 2000. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP6 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
The LsaQueryInformationPolicy() function can be used to retrieve an NT domain's SID from any workstation in that domain. This can be done remotely by an anonymous user through a null session. That SID can then be used to obtain lists of user's names and SIDs for brute force attacks.
The LsaQueryInformationPolicy() function can be used to retrieve an NT domain's SID from any workstation in that domain. This can be done remotely by an anonymous user through a null session. That SID can then be used to obtain lists of user's names and SIDs for brute force attacks.
Exploit / POC
NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
NT LsaQueryInformationPolicy() Domain SID Leak Vulnerability
References:
References: