PT-2007-4296 · Microsoft · Windows Server 2003
Publicado
2007-06-04
·
Atualizado
2012-11-06
·
CVE-2007-2999
CVSS v2.0
1.8
Baixa
| Vetor | AV:A/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows Server 2003
Description:
The issue allows context-dependent attackers to determine valid Active Directory account names by generating different error messages for failed login attempts with a valid user name than for those with an invalid user name when time restrictions are in effect for user accounts.
Recommendations:
For Microsoft Windows Server 2003, consider implementing additional authentication logging and monitoring to detect and respond to potential attacks, and restrict access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows Server 2003