Today I found DSquery on one of my smb shares at work. I ran it to query users and since my company uses IC numbers as the unique CN, I got to see all my colleagues' ICs.
Firstly, is this considered a vulnerability? and secondly how can this be mitigated? From another question on serverfault there seems to be no sure way to harden the AD in this manner to mitigate against such attacks. Attacker will just need any user account and since this is a smb share on the AD SYSVOL, any windows box connected to the domain can be used to exploit this.