Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1138

Опубликовано: 10 июн. 2009
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.58555
Средний

10 Critical

CVSS2

Дефекты

CWE-399

Связанные уязвимости

github
почти 4 года назад

The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.

EPSS

Процентиль: 98%
0.58555
Средний

10 Critical

CVSS2

Дефекты

CWE-399