Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2000-1200


Vulnerability Score 5.0 5.0
CVE Id CVE-2000-1200
Last Modified 05 Sep 2008 04:22:54
Published 31 Aug 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

Vulnerable Systems

Operating System

  • Microsoft Windows Nt 4.0


XF - nt-lsa-domain-sid(4015)

BID - 959

BUGTRAQ - 20000201 Windows NT and account list leak ! A new SID usage

Last Updated: 27 May 2016 10:36:04