Microsoft Windows SMB 來賓帳戶的本機使用者存取權

high Nessus Plugin ID 26919

概要

It is possible to log into the remote host.

說明

遠端主機正在執行其中一種 Microsoft Windows 作業系統或 SAMBA 精靈。來賓使用者若使用隨機帳戶,則不能登入。

解決方案

In the group policy change the setting for 'Network access: Sharing and security model for local accounts' from 'Guest only - local users authenticate as Guest' to 'Classic - local users authenticate as themselves'. Disable the Guest account if applicable.

If the SAMBA daemon is running, double-check the SAMBA configuration around guest user access and disable guest access if appropriate

Plugin 詳細資訊

嚴重性: High

ID: 26919

檔案名稱: smb_guest_account.nasl

版本: 1.19

類型: remote

代理程式: windows

系列: Windows

已發布: 2007/10/4

已更新: 2020/9/21

支援的感應器: Nessus

風險資訊

CVSS 評分論據: Av:n is justified since the plugin tries to login via network services. nist specifies that the vulnerability pertains to a domain user. given that the plugin only tests for a guest account, which likely has limited permissions, the cia is partial instead of complete.

VPR

風險因素: Medium

分數: 5.9

CVSS v2

風險因素: High

基本分數: 7.5

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-1999-0505

弱點資訊

CPE: cpe:/o:microsoft:windows

必要的 KB 項目: SMB/guest_enabled

可被惡意程式利用: true

可輕鬆利用: Exploits are available

弱點發布日期: 1999/1/1

可惡意利用

Metasploit (Microsoft Windows Authenticated Powershell Command Execution)

參考資訊

CVE: CVE-1999-0505