PT-2007-3565 · Microsoft · Windows Vista X64 Edition+7
Publicado
2007-10-09
·
Atualizado
2018-10-16
·
CVE-2007-2228
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 SP1
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows Server 2003 x64 Edition SP2
Microsoft Windows Vista
Microsoft Windows Vista x64 Edition
Microsoft Windows 2000 SP4
Description
A denial of service issue exists due to a failure in communicating with the NTLM security provider when performing authentication of RPC requests. An attacker could exploit this by sending a specially crafted RPC authentication request to a computer over the network, causing the computer to stop responding and automatically restart. In the case of Windows 2000 SP4, the impact is an information leak.
Recommendations
For Microsoft Windows XP SP2, update to a newer version to mitigate the risk.
For Microsoft Windows XP Professional x64 Edition, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 SP1, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 x64 Edition, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 x64 Edition SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Vista, update to a newer version to mitigate the risk.
For Microsoft Windows Vista x64 Edition, update to a newer version to mitigate the risk.
For Microsoft Windows 2000 SP4, restrict access to the NTLM security provider to minimize the risk of information leak.
As a temporary workaround, consider disabling the RPC facility until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows
Windows 2000
Windows Server 2003
Windows Server 2003 X64 Edition
Windows Vista
Windows Vista X64 Edition
Windows Xp
Windows Xp Professional X64 Edition