| Microsoft Windows Knowledge Base Article 971055 update is not installed (WinMs09kb971055Update) |
|---|
| Vuln ID: | 50767 | |
|---|---|---|
| Risk Level: | High |
WinMs09kb971055Update |
| Platforms: | Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2 Professional, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Windows XP: SP3 Professional | |
| Description: | Microsoft Knowledge Base Article 971055 is not installed, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft Windows 2000 could allow a remote attacker to execute arbitrary code on the system, caused by improper freeing of memory by the Active Directory Lightweight Directory Access Protocol (LDAP) service. By sending a specially-crafted crafted LDAP or LDAPS request to a Microsoft Windows 2000 Domain Controller, an attacker could exploit this vulnerability to execute arbitrary code with the privileges of the victim. Microsoft Windows is vulnerable to a denial of service, caused by a memory leak error in the Active Directory and Active Directory Application Mode (ADAM) Lightweight Directory Access Protocol (LDAP) service. By sending a specially-crafted LDAP or LDAPS request containing specific OID filters to the ADAM or an Active Directory server, a remote attacker could exploit this vulnerability to cause the system to stop responding. The system must be rebooted to regain normal functionality. Note: Authentication is required to exploit this vulnerability on Windows Server 2003 or systems with ADAM installed. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS09-018. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS09-018 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2009-1138 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |