← Vulnerability feed

Vulnerability record · CVE-2000-1200 · published 31 August 2001

CVE-2000-1200: Windows NT null session leaks domain SID and user list

Microsoft · Windows Nt

Windows NT permits an unauthenticated remote attacker to obtain the domain SID through the LsaQueryInformationPolicy policy function over a null session, then use that SID to enumerate all users in the domain. The flaw exposes directory information that should require authentication, which aids reconnaissance and follow-on attacks against accounts.

5.0 CVSS 2.0 Medium EPSS 48% · top 1.2%
5.0CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is an unauthenticated information disclosure with public exploit references and high EPSS, but it only leaks account data and affects an obsolete platform, limiting direct impact.

What it is

Windows NT permits an unauthenticated remote attacker to obtain the domain SID through the LsaQueryInformationPolicy policy function over a null session, then use that SID to enumerate all users in the domain. The flaw exposes directory information that should require authentication, which aids reconnaissance and follow-on attacks against accounts.

Impact

An attacker gains a complete list of domain user accounts and the domain SID without credentials. This information supports username harvesting, password guessing and further targeting of valid accounts.

Attack surface

Reachable over the network via SMB null session calls to the LSA policy interface; no authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.

Exploitation

The record is not in CISA KEV and documents no ransomware use, but reference tags include Exploit and EPSS is 0.481 (98.8th percentile), indicating public exploit material and elevated predicted activity.

What to do

  • Apply the vendor patch referenced in the SecurityFocus advisory and keep Windows NT systems fully updated.
  • Disable null session access by restricting anonymous SMB access (e.g., RestrictAnonymous) and blocking anonymous enumeration of SAM accounts and shares.
  • Block inbound SMB (TCP 139/445) from untrusted networks at the perimeter and between segments.
  • Retire or isolate unsupported Windows NT systems that cannot be patched.
  • Audit domain account naming and monitor for enumeration attempts against legacy hosts.

Detection

  • Monitor SMB and LSA policy RPC traffic for null session establishment followed by LsaQueryInformationPolicy or user enumeration calls.
  • Alert on anonymous logon events (event ID 528/540 with logon type 3 and null credentials) on legacy Windows NT hosts.
  • Baseline and flag spikes in domain account enumeration or repeated SID lookups from a single source.
  • Review firewall and IDS logs for SMB connections to Windows NT systems from unexpected external or cross-segment sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed7.8CVE-2002-0367Windows NT/2000 smss.exe debugging subsystem privilege escalationThe smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a lo…KEVEPSS 4.9%analysed10.0CVE-2005-0050Windows License Logging Service buffer overflow via unvalidated message lengthThe License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an …EPSS 47%analysed10.0CVE-2004-0568Microsoft windows 2000 vulnerabilityHyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that…EPSS 35%10.0CVE-2004-0571Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…EPSS 31%10.0CVE-2004-0900Microsoft windows nt vulnerabilityThe DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, wh…EPSS 26%10.0CVE-2004-0901Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…EPSS 32%10.0CVE-2004-1080Microsoft WINS Service Memory Corruption via Replication PacketThe WINS service (wins.exe) on Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 mishandles a modified memory pointer in a WINS rep…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2000-1200), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.