|
Windows contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when documented Windows API calls (such as the LsaQueryInformationPolicy() function) are used to query the system and disclose the SID. Used in conjunction with other function, a remote attacker can then enumerate account information, resulting in a loss of confidentiality.
|