CVE-2007-3898
Published Nov 14, 2007
Last updated 3 years ago
Overview
- Description
- The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
- Source
- secure@microsoft.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-16
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FA4B3F6-3677-49D7-838C-132C9FB16EC4" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:adv_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0754FF1B-87C1-4AAC-B251-BD8CB5C25587" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:datacenter_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4FFC9CB-DA0E-4C2E-89E4-1B59AA9AFBC7" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C53873F9-359A-47B5-9B07-B79A8DE4E7AA" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "294EBA01-147B-4DA0-937E-ACBB655EDE53" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:adv_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28EC4E15-AD21-4546-98B9-923A8F7FECD4" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:datacenter_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FB07F10-C360-4E6A-B275-76500CA2D909" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E2611F2-9DF4-4A2A-BCF1-62AA80607F22" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E8B7346-F2AA-434C-A048-7463EC1BB117" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:adv_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE187844-D785-4E72-8795-2F982254FF5F" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:datacenter_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B9E92BD-3545-4F85-B14E-E891AAA40E67" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E877034-F364-4F93-8875-0A39D0175668" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE1A6107-DE00-4A1C-87FC-9E4015165B5B" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:adv_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47F2519C-6A5F-4BA9-B413-6F0850F600D7" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:datacenter_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1DF5921-C2FA-471C-ABD8-15E29E466143" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D71BB9C7-84BE-4B0A-A3B4-C96E6D3D9342" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:adv_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C9E8E3E-0356-423E-8649-297DE7037E9F" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:datacenter_srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF583F20-FED0-4218-B8B4-818DF86082EE" }, { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:srv:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F200FFC6-7D0E-4500-AB65-8785FD1EEC24" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F3C557A-71D8-47F9-9E12-CE938F301E66" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:itanium:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81C8959A-915B-472F-B043-A57BA11FDB93" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:std:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00C55EE5-2F70-4DC3-937A-BB5F13AC078E" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B92137A3-71F9-466B-87CA-F3E9EF53AE4B" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64-std:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "115D2DE5-8F40-441C-8783-430668AEE356" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE8F4276-4D97-480D-A542-FE9982FFD765" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:std:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30A3D604-7DC9-42F3-9DB1-AF32CA4C8BDA" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2978BF86-5A1A-438E-B81F-F360D0E30C9C" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7EFB032-47F4-4497-B16B-CB9126EAC9DF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:std:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA1482B6-C9A1-497A-8CD7-63F9F7CEAB3C" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6881476D-81A2-4DFD-AC77-82A8D08A0568" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D826455B-E635-4FB2-9428-81028E10D98F" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA778424-6F70-4AB6-ADD5-5D4664DFE463" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D3B5E4F-56A6-4696-BBB4-19DF3613D020" } ], "operator": "OR" } ] } ]