PT-2010-2546 · Microsoft · Windows Server 2008+7

Published

2010-09-15

·

Updated

2024-10-17

·

CVE-2010-0820

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2008 Gold, SP2, and R2 Microsoft Windows XP SP2 and SP3 Microsoft Windows Vista SP2 Microsoft Windows 7 Microsoft Windows Server 2008 Gold, SP2, and R2 Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2 Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
Description The issue is a heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS) as used in Active Directory, allowing remote authenticated users to execute arbitrary code via malformed LDAP messages.
Recommendations For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk. For Microsoft Windows Server 2008 Gold, SP2, and R2, update to a newer version to mitigate the risk. For Microsoft Windows XP SP2 and SP3, update to a newer version to mitigate the risk. For Microsoft Windows Vista SP2, update to a newer version to mitigate the risk. For Microsoft Windows 7, update to a newer version to mitigate the risk. For Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2, update to a newer version to mitigate the risk. For Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, update to a newer version to mitigate the risk.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2010-0820

Affected Products

Active Directory Application Mode
Active Directory Lightweight Directory Service
Local Security Authority Subsystem Service
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp