Lucene search

K
cve[email protected]CVE-2007-1748
HistoryApr 13, 2007 - 6:19 p.m.

CVE-2007-1748

2007-04-1318:19:00
CWE-119
web.nvd.nist.gov
46
cve-2007-1748
buffer overflow
rpc interface
dns server
microsoft windows
remote code execution
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.6 High

AI Score

Confidence

High

0.969 High

EPSS

Percentile

99.7%

Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.

Affected configurations

NVD
Node
microsoftwindows_2000sp4
OR
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_2003_serverMatchsp1itanium
OR
microsoftwindows_2003_serverMatchsp1x64
OR
microsoftwindows_2003_serverMatchsp2
OR
microsoftwindows_2003_serverMatchsp2itanium
OR
microsoftwindows_2003_serverMatchsp2x64

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.6 High

AI Score

Confidence

High

0.969 High

EPSS

Percentile

99.7%