7.8

CVE-2007-2228

rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference.  NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Edition x64
Microsoft ≫ Windows 2003 Server Update sp2 Edition x64
Microsoft ≫ Windows Vista Edition x64
Microsoft ≫ Windows Xp Edition professional
Microsoft ≫ Windows Xp Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.3% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/archive/1/482366/100/0/threaded
http://www.us-cert.gov/cas/techalerts/TA07-282A.html
US Government Resource
http://secunia.com/advisories/27134
Vendor Advisory
http://secunia.com/advisories/27153
Vendor Advisory
http://securitytracker.com/id?1018787
http://www.securityfocus.com/archive/1/482023/100/0/threaded
http://www.securityfocus.com/bid/25974
http://www.vupen.com/english/advisories/2007/3438
Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-055.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-058
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2310