|
Family: Windows --> Category: infos
SMB Registry : Winlogon caches passwords Vulnerability Scan
Vulnerability Scan Summary Acertains the value of a remote key
Detailed Explanation for this Vulnerability Test
Synopsis :
User credentials are stored in memory.
Description :
The registry key
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CachedLogonsCount
is non-null. It means that the remote host locally caches the passwords
of the users when they log in, in order to continue to allow the users
to log in in the case of the failure of the PDC.
Solution :
use regedt32 and set the value of this key to 0
Threat Level:
Low / CVSS Base Score : 1
(AV:L/AC:H/Au:R/C:P/A:N/I:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|