H3-2023-0030
Active Directory - User Password Not Required
Category | SECURITY_MISCONFIGURATION |
Base Score | 4.3 |
Description
User objects within Active Directory have attributes that can be added/deleted/edited by a privileged user. The userAccountControl attribute has a PASSWD_NOTREQD flag that, if set, allows a User to not have a password. However, This does not mean the user actually has a blank password, just that is is possible.",
Impact
An authenticated user could discover an enabled user with the PASSWD_NOTREQD flag set and may be able to login as that user without a password.