CVE-2003-0507: Buffer Overflow
Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft Windows 2000to a version that resolves this vulnerability.Fixed in SP4
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0507?
CVE-2003-0507 has a severity rating that indicates a significant risk due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2003-0507?
To fix CVE-2003-0507, it is recommended to apply the latest service pack updates for Windows 2000, specifically Service Pack 4 or later.
What systems are affected by CVE-2003-0507?
CVE-2003-0507 primarily affects Windows 2000 systems prior to Service Pack 4.
What type of attack can exploit CVE-2003-0507?
CVE-2003-0507 can be exploited through a remote attack using a modified LDAP version 3 search request.
What are the consequences of CVE-2003-0507 exploitation?
Exploitation of CVE-2003-0507 can lead to a system reboot and potentially allow an attacker to run arbitrary code on the vulnerable system.