7.8
CVE-2007-2228
- EPSS 43.3%
- Veröffentlicht 09.10.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:39:10
- Erkennungen
rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Edition x64
Microsoft ≫ Windows 2003 Server Update sp1
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 2003 Server Update sp2 Edition x64
Microsoft ≫ Windows Vista Edition x64
Microsoft ≫ Windows Xp Edition professional
Microsoft ≫ Windows Xp Update sp2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 43.3% | 0.986 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
http://www.securityfocus.com/archive/1/482366/100/0/threaded
http://www.us-cert.gov/cas/techalerts/TA07-282A.html
http://secunia.com/advisories/27134
http://secunia.com/advisories/27153
http://securitytracker.com/id?1018787
http://www.securityfocus.com/archive/1/482023/100/0/threaded
http://www.securityfocus.com/bid/25974
http://www.vupen.com/english/advisories/2007/3438
http://www.zerodayinitiative.com/advisories/ZDI-07-055.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-058
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2310