Could the attacker change the group policy on the Windows 2000 domain controller?
No. The vulnerability would only allow the attacker to change the data received by the client. It would not provide any way to change the data as it resides on the server. Why have you discussed the domain controller scenario only in the context of Windows 2000? Windows XP cannot be used as a domain controller. As a result, this scenario – which is the highest-risk scenario associated with the vulnerability – doesn’t apply to Windows XP. I heard that Windows XP clients can inadvertently trigger the vulnerability. Is this true? Yes. Windows XP Service Pack 1 contained a regression error that adds information to the negotiation information it sends. This information can trigger the vulnerability, and cause systems running Windows XP Gold or Windows 2000 to drop SMB signing. A fix is available to eliminate this regression error. It is important to understand two critical points regarding the regression error in Windows XP Service Pack 1: * The regression error poses no security threat to