Network misconfigurations

Azure virtual machine with Windows distribution allows direct public NetBIOS datagram distribution service access

Description

NetBIOS provides services related to the session layer of the OSI model allowing applications on separate computers to communicate over a local area network. Port 138 is using for datagram distribution service - connectionless communication. This port is open on your Windows virtual machine and allows all incoming traffic from the Internet. In order to keep security best practices and decrease the risk for malicious activities, you should restrict access to be only from allowed IP addresses.
  • Recommended Mitigation

    Configure networking rule to allow incoming NetBIOS traffic from allowed IP addresses only.