CVE-2007-3028

Windows 2000 Server SP4 - Denial of Service via Crafted LDAP Request

Title source: llm
STIX 2.1

Description

The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.

References (9)

Core 9
Core References
Various Sources vendor-advisory x_refsource_hp
http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24796
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018355
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26002
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2481
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-191A.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/348953
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1856

Scores

EPSS 0.3967
EPSS Percentile 98.5%

Details

Status published
Products (1)
microsoft/windows_2000
Published Jul 10, 2007
Tracked Since Feb 18, 2026