PT-2007-1533 · Microsoft · Windows 2000 Server+3

Published

2007-07-10

·

Updated

2019-04-30

·

CVE-2007-0040

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 Server version SP4 Microsoft Windows Server 2003 version SP1 Microsoft Windows Server 2003 version SP2 Microsoft Windows Server 2003 x64 Edition version SP2 Microsoft Windows Server 2003 for Itanium-based Systems version SP1 Microsoft Windows Server 2003 for Itanium-based Systems version SP2
Description The issue allows remote attackers to execute arbitrary code via a crafted LDAP request. This is made possible by an unspecified number of "convertible attributes" in the LDAP service within Windows Active Directory.
Recommendations For Microsoft Windows 2000 Server SP4, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 SP1, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 x64 Edition SP2, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 for Itanium-based Systems SP1, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 for Itanium-based Systems SP2, update to a newer version to mitigate the risk.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0040

Affected Products

Windows 2000 Server
Windows Server 2003
Windows Server 2003 For Itanium-Based Systems
Windows Server 2003 X64 Edition