PT-2007-4296 · Microsoft · Windows Server 2003

Publicado

2007-06-04

·

Atualizado

2012-11-06

·

CVE-2007-2999

CVSS v2.0

1.8

Baixa

VetorAV:A/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows Server 2003
Description: The issue allows context-dependent attackers to determine valid Active Directory account names by generating different error messages for failed login attempts with a valid user name than for those with an invalid user name when time restrictions are in effect for user accounts.
Recommendations: For Microsoft Windows Server 2003, consider implementing additional authentication logging and monitoring to detect and respond to potential attacks, and restrict access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2999

Produtos afetados

Windows Server 2003