Synopsis
The remote web server is a certificate enrollment server that anyone can access without credentials.
Description
The remote web server is running the Microsoft Certificate Services.
However, the service is misconfigured in such a way that anonymous users can log into the service to request certificates, thus breaking the chain of trust.
Solution
Edit the remote web server configuration to force authentication prior to accessing the remote resource.
Plugin Details
File Name: microsoft_certsrv_anon_detect.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning