|
|
|
![]() |
Vulnerability Note VU#348953Microsoft Windows Active Directory fails to properly validate client sent LDAP requestsOverviewMicrosoft Windows Active Directory fails to properly validate client-sent LDAP requests and may result in a denial of service condition.I. DescriptionMicrosoft Windows Active Directory contains a vulnerability in the way that the LDAP service validates the number of convertible attributes in the client-sent request. By sending a specially crafted LDAP request to a server running Active Directory, an attacker may be able to cause the server to stop responding.II. ImpactA remote attacker may be able to cause a denial of service condition.III. SolutionApply an UpdateMicrosoft has released updates in Microsoft Security Bulletin MS07-039 to address this issue.
References
This vulnerability was reported in Microsoft Security Bulletin MS07-039. Microsoft credits Peter Winter-Smith of NGSSoftware for reporting the vulnerability to them. This document was written by Katie Steiner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||