Home / bulletins

MS07-039 - Critical: Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122) - Version:1.0

Posted on 11 July 2007

There is an newer version: MS07-039 - Version: 1.1

Critical

Severity Rating: Critical - Revision Note: Bulletin published.Summary: This critical security update resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. This is a critical security update for supported editions of Windows 2000 and an important security update for supported editions of Windows Server 2003. For more information, see the subsection, Affected and Non-Affected Software, in this section. This security update addresses the vulnerability by validating the number of convertible attributes in the client LDAP request.

Link

Other versions

 

TOP