PT-2007-1533 · Microsoft · Windows 2000 Server+3
Published
2007-07-10
·
Updated
2019-04-30
·
CVE-2007-0040
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 Server version SP4
Microsoft Windows Server 2003 version SP1
Microsoft Windows Server 2003 version SP2
Microsoft Windows Server 2003 x64 Edition version SP2
Microsoft Windows Server 2003 for Itanium-based Systems version SP1
Microsoft Windows Server 2003 for Itanium-based Systems version SP2
Description
The issue allows remote attackers to execute arbitrary code via a crafted LDAP request. This is made possible by an unspecified number of "convertible attributes" in the LDAP service within Windows Active Directory.
Recommendations
For Microsoft Windows 2000 Server SP4, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 SP1, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 x64 Edition SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 for Itanium-based Systems SP1, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 for Itanium-based Systems SP2, update to a newer version to mitigate the risk.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000 Server
Windows Server 2003
Windows Server 2003 For Itanium-Based Systems
Windows Server 2003 X64 Edition