<< Back
CVE Number Vulnerability Product Severity Date
MS07-039 Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122) Microsoft Windows Critical 11-07-2007

Technical Information

Brief overview of the risk:
This critical security update resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
Detailed Information on the risk:
A remote code execution vulnerability exists in the way that Active Directory validates a LDAP request. An attacker who successfully exploited this vulnerability could take complete control of an affected system.Further information on this exploit is available at : MS07-039

Affected Software

Microsoft Windows 2000 Server Service Pack 4
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition
Service Pack 2
Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 forItanium-based Systems