PT-2010-1860 · Microsoft · Windows Server 2003+3
Published
2010-02-10
·
Updated
2019-04-30
·
CVE-2010-0035
CVSS v2.0
6.3
Medium
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 Gold
Microsoft Windows Server 2008 SP2
Description
The Key Distribution Center (KDC) in Kerberos in Microsoft Windows, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service via a crafted Ticket Granting Ticket (TGT) renewal request. This can result in a NULL pointer dereference and domain controller outage.
Recommendations
For Microsoft Windows 2000 SP4, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2008 Gold, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2008 SP2, update to a version that includes the fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kerberos
Windows 2000
Windows Server 2003
Windows Server 2008