5

CVE-2000-1200

Exploit

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows Nt Version4.0
MicrosoftWindows Nt Version4.0 Updatesp1
MicrosoftWindows Nt Version4.0 Updatesp2
MicrosoftWindows Nt Version4.0 Updatesp3
MicrosoftWindows Nt Version4.0 Updatesp4
MicrosoftWindows Nt Version4.0 Updatesp5
MicrosoftWindows Nt Version4.0 Updatesp6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 20.5% 0.95
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N