This application requires Javascript for optimal performance.

MS.Windows.Active.Directory.LDAP.Request.Remote.Code.Execution

Release Date

Dec 31, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Remote Code Execution vulnerability in Microsoft Windows Active Directory.

The vulnerability is a result of the software's failure to handle specially crafted Lightweight Directory Access Protocol (LDAP) requests. A remote attacker can exploit this to execute arbitrary code with SYSTEM privileges.

Affected Products

Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 x64 SP1
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows Server 2003 Itanium 0
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP1

Recommended Actions

Apply patch, available from the website:
http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-0040

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS07-039.mspx (MS-ID)
http://www.securityfocus.com/bid/24800 (BugTraq)
http://www.frsirt.com/english/advisories/2007/2481 (FrSIRT)

Reference: VID-30412