Information disclosure in Windows and Windows Server - CVE-2024-20692
Published: January 9, 2024
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the Microsoft Local Security Authority Subsystem Service. A remote user can trick a victim to connect to an Active Directory Domain Controller and then steal network secrets.