Vulnerability record · CVE-2000-1200 · published 31 August 2001
CVE-2000-1200: Windows NT null session leaks domain SID and user list
Microsoft · Windows Nt
Windows NT permits an unauthenticated remote attacker to obtain the domain SID through the LsaQueryInformationPolicy policy function over a null session, then use that SID to enumerate all users in the domain. The flaw exposes directory information that should require authentication, which aids reconnaissance and follow-on attacks against accounts.
Description
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityThe flaw is an unauthenticated information disclosure with public exploit references and high EPSS, but it only leaks account data and affects an obsolete platform, limiting direct impact.
What it is
Windows NT permits an unauthenticated remote attacker to obtain the domain SID through the LsaQueryInformationPolicy policy function over a null session, then use that SID to enumerate all users in the domain. The flaw exposes directory information that should require authentication, which aids reconnaissance and follow-on attacks against accounts.
Impact
An attacker gains a complete list of domain user accounts and the domain SID without credentials. This information supports username harvesting, password guessing and further targeting of valid accounts.
Attack surface
Reachable over the network via SMB null session calls to the LSA policy interface; no authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
The record is not in CISA KEV and documents no ransomware use, but reference tags include Exploit and EPSS is 0.481 (98.8th percentile), indicating public exploit material and elevated predicted activity.
What to do
- Apply the vendor patch referenced in the SecurityFocus advisory and keep Windows NT systems fully updated.
- Disable null session access by restricting anonymous SMB access (e.g., RestrictAnonymous) and blocking anonymous enumeration of SAM accounts and shares.
- Block inbound SMB (TCP 139/445) from untrusted networks at the perimeter and between segments.
- Retire or isolate unsupported Windows NT systems that cannot be patched.
- Audit domain account naming and monitor for enumeration attempts against legacy hosts.
Detection
- Monitor SMB and LSA policy RPC traffic for null session establishment followed by LsaQueryInformationPolicy or user enumeration calls.
- Alert on anonymous logon events (event ID 528/540 with logon type 3 and null credentials) on legacy Windows NT hosts.
- Baseline and flag spikes in domain account enumeration or repeated SID lookups from a single source.
- Review firewall and IDS logs for SMB connections to Windows NT systems from unexpected external or cross-segment sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/44430 | Vendor Advisory |
| http://www.securityfocus.com/bid/959 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/4015 | |
| http://www.securityfocus.com/archive/1/44430 | Vendor Advisory |
| http://www.securityfocus.com/bid/959 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/4015 |
Track CVE-2000-1200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-1200), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.