QID70003 is reported for 2012 R2 Domain controllers

Techshan 216 Reputation points
2020-09-01T07:14:01.257+00:00

QID70003 Null Session/Password NetBIOS Access is being reported in Domain controllers ,

Anyone please suggest is this really a vulnerability or not applicable for Windows 2012 R2

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,564 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 20,791 Reputation points Microsoft Vendor
    2020-09-02T08:20:41.12+00:00

    Hello @SHANMUGAMSWAMINATHAN-5167,

    Thank you for posting here.

    We can check if "Anonymous Logon" is the member of "Pre-Windows 2000 Compatible Access" built-in domain group or if "Anonymous Logon" is under Security tab of "Pre-Windows 2000 Compatible Access" built-in domain group.
    22027-pre.png

    If so, we can try to remove it to see if it helps.

    Here is a similar case we can refer to.

    Qualys showing "Null Session/Password NetBIOS Access" on DCs - Not Sure How/If this can be fixed.
    https://social.technet.microsoft.com/Forums/en-US/6bf6e366-8be2-4cfd-a5ec-3be4396a6f6d/qualys-showing-quotnull-sessionpassword-netbios-accessquot-on-dcs-not-sure-howif-this-can-be?forum=winserverDS

    If it does not work,

    1.Would you please tell us what you are doing then QID70003 is reported for 2012 R2 Domain controllers?

    2.Did you scan DC using one vulnerability scan tool?

    Best Regards,
    Daisy Zhou

    0 comments No comments