6.4

CVE-2007-3898

Exploit

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2000 Updategold
MicrosoftWindows 2000 Updategold Editionadv_srv
MicrosoftWindows 2000 Updategold Editiondatacenter_srv
MicrosoftWindows 2000 Updategold Editionsrv
MicrosoftWindows 2000 Updatesp1
MicrosoftWindows 2000 Updatesp1 Editionadv_srv
MicrosoftWindows 2000 Updatesp1 Editiondatacenter_srv
MicrosoftWindows 2000 Updatesp1 Editionsrv
MicrosoftWindows 2000 Updatesp2
MicrosoftWindows 2000 Updatesp2 Editionadv_srv
MicrosoftWindows 2000 Updatesp2 Editiondatacenter_srv
MicrosoftWindows 2000 Updatesp2 Editionsrv
MicrosoftWindows 2000 Updatesp3
MicrosoftWindows 2000 Updatesp3 Editionadv_srv
MicrosoftWindows 2000 Updatesp3 Editiondatacenter_srv
MicrosoftWindows 2000 Updatesp3 Editionsrv
MicrosoftWindows 2000 Updatesp4
MicrosoftWindows 2000 Updatesp4 Editionadv_srv
MicrosoftWindows 2000 Updatesp4 Editiondatacenter_srv
MicrosoftWindows 2000 Updatesp4 Editionsrv
MicrosoftWindows 2003 Server Updategold Editionitanium
MicrosoftWindows 2003 Server Updategold Editionstd
MicrosoftWindows 2003 Server Updategold Editionx64
MicrosoftWindows 2003 Server Updategold Editionx64-std
MicrosoftWindows 2003 Server Updatesp1 Editionstd
MicrosoftWindows 2003 Server Updatesp2 Editionitanium
MicrosoftWindows 2003 Server Updatesp2 Editionstd
MicrosoftWindows 2003 Server Updatesp2 Editionx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 83.87% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P