MS.Windows.Session.Information.Disclosure

description-logoDescription

This is an information disclosure vulnerability. An attacker who successfully exploited this vulnerability could remotely read the user names of users who have an open connection to a shared resource.
The process that is used by the affected software to validate authentication information when a client establishes an anonymous logon by using a named pipe connection.

affected-products-logoAffected Products

Microsoft Windows XP (all versions)

Impact logoImpact

Disclosure of sensitive system information

recomended-action-logoRecommended Actions

Microsoft has released a critical update to fix this vulnerability. Please apply update MS05-007 on all affected systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)