VID |
27136 |
Severity |
30 |
Port |
135 |
Protocol |
TCP |
Class |
DB |
Detailed Description |
There is no access restriction on the system shared directory.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* Platforms Affected: Microsoft Windows Any version |
Recommendation |
[Control Panel / Administrative Tools / Local Security Policy / Local Policies / Security Options]: ???? [Do not allow enumeration of anonymous connections from SAM accounts and shares] ???? Confirm [Do not allow anonymous enumeration of SAM accounts] ???? Check [Apply Everyone permission to anonymous users] ???? Confirm Anonymous Access Restrictions on Named Pipes and Shares |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|