CVE-2007-1748
Published Apr 13, 2007
Last updated 6 years ago
Overview
- Description
- Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
- Source
- secure@microsoft.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "644E2E89-F3E3-4383-B460-424D724EE62F" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D11FC8D-59DD-4CAC-B4D3-DABB7A9903F1" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0507FBE-8679-4CE3-946A-E91CD8DAEC41" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "377F7D0C-6B44-4B90-BF90-DAF959880C6D" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D21D1DFE-F61B-407E-A945-4F42F86947B0" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3461CEA0-6CCF-4AA9-B83A-420E1310C83C" } ], "operator": "OR" } ] } ]