PT-2010-2546 · Microsoft · Windows Server 2008+7
Published
2010-09-15
·
Updated
2024-10-17
·
CVE-2010-0820
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 Gold, SP2, and R2
Microsoft Windows XP SP2 and SP3
Microsoft Windows Vista SP2
Microsoft Windows 7
Microsoft Windows Server 2008 Gold, SP2, and R2
Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2
Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
Description
The issue is a heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS) as used in Active Directory, allowing remote authenticated users to execute arbitrary code via malformed LDAP messages.
Recommendations
For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2008 Gold, SP2, and R2, update to a newer version to mitigate the risk.
For Microsoft Windows XP SP2 and SP3, update to a newer version to mitigate the risk.
For Microsoft Windows Vista SP2, update to a newer version to mitigate the risk.
For Microsoft Windows 7, update to a newer version to mitigate the risk.
For Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, update to a newer version to mitigate the risk.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Active Directory Application Mode
Active Directory Lightweight Directory Service
Local Security Authority Subsystem Service
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp