{ "id": "CVE-2007-3898", "sourceIdentifier": "secure@microsoft.com", "published": "2007-11-14T01:46:00.000", "lastModified": "2021-07-07T16:09:32.553", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors." }, { "lang": "es", "value": "El servidor DNS en Microsoft Windows 2000 Server SP4, y Server 2003 SP1 y SP2, utiliza transacciones predecibles IDs cuando consultan otros servidores DNS, lo cual permite a atacantes remotos suplantando respuestas DNS, envenenar la cache DNS, y facilitar vectores de ataque m\u00e1s adelante." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.4 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-16" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*", "matchCriteriaId": "7FA4B3F6-3677-49D7-838C-132C9FB16EC4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:adv_srv:*:*:*:*:*", "matchCriteriaId": "0754FF1B-87C1-4AAC-B251-BD8CB5C25587" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:datacenter_srv:*:*:*:*:*", "matchCriteriaId": "E4FFC9CB-DA0E-4C2E-89E4-1B59AA9AFBC7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:gold:srv:*:*:*:*:*", "matchCriteriaId": "C53873F9-359A-47B5-9B07-B79A8DE4E7AA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*", "matchCriteriaId": "294EBA01-147B-4DA0-937E-ACBB655EDE53" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:adv_srv:*:*:*:*:*", "matchCriteriaId": "28EC4E15-AD21-4546-98B9-923A8F7FECD4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:datacenter_srv:*:*:*:*:*", "matchCriteriaId": "7FB07F10-C360-4E6A-B275-76500CA2D909" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:srv:*:*:*:*:*", "matchCriteriaId": "3E2611F2-9DF4-4A2A-BCF1-62AA80607F22" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*", "matchCriteriaId": "4E8B7346-F2AA-434C-A048-7463EC1BB117" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:adv_srv:*:*:*:*:*", "matchCriteriaId": "EE187844-D785-4E72-8795-2F982254FF5F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:datacenter_srv:*:*:*:*:*", "matchCriteriaId": "1B9E92BD-3545-4F85-B14E-E891AAA40E67" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:srv:*:*:*:*:*", "matchCriteriaId": "2E877034-F364-4F93-8875-0A39D0175668" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*", "matchCriteriaId": "BE1A6107-DE00-4A1C-87FC-9E4015165B5B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:adv_srv:*:*:*:*:*", "matchCriteriaId": "47F2519C-6A5F-4BA9-B413-6F0850F600D7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:datacenter_srv:*:*:*:*:*", "matchCriteriaId": "F1DF5921-C2FA-471C-ABD8-15E29E466143" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:srv:*:*:*:*:*", "matchCriteriaId": "D71BB9C7-84BE-4B0A-A3B4-C96E6D3D9342" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:adv_srv:*:*:*:*:*", "matchCriteriaId": "8C9E8E3E-0356-423E-8649-297DE7037E9F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:datacenter_srv:*:*:*:*:*", "matchCriteriaId": "BF583F20-FED0-4218-B8B4-818DF86082EE" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:srv:*:*:*:*:*", "matchCriteriaId": "F200FFC6-7D0E-4500-AB65-8785FD1EEC24" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:*:*:*:*:*:*", "matchCriteriaId": "6F3C557A-71D8-47F9-9E12-CE938F301E66" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:itanium:*:*:*:*:*", "matchCriteriaId": "81C8959A-915B-472F-B043-A57BA11FDB93" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:std:*:*:*:*:*", "matchCriteriaId": "00C55EE5-2F70-4DC3-937A-BB5F13AC078E" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64:*:*:*:*:*", "matchCriteriaId": "B92137A3-71F9-466B-87CA-F3E9EF53AE4B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64-std:*:*:*:*:*", "matchCriteriaId": "115D2DE5-8F40-441C-8783-430668AEE356" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*", "matchCriteriaId": "FE8F4276-4D97-480D-A542-FE9982FFD765" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:std:*:*:*:*:*", "matchCriteriaId": "30A3D604-7DC9-42F3-9DB1-AF32CA4C8BDA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*", "matchCriteriaId": "2978BF86-5A1A-438E-B81F-F360D0E30C9C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*", "matchCriteriaId": "F7EFB032-47F4-4497-B16B-CB9126EAC9DF" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:std:*:*:*:*:*", "matchCriteriaId": "BA1482B6-C9A1-497A-8CD7-63F9F7CEAB3C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*", "matchCriteriaId": "6881476D-81A2-4DFD-AC77-82A8D08A0568" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:-:*:*:*:*:*:*", "matchCriteriaId": "D826455B-E635-4FB2-9428-81028E10D98F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*", "matchCriteriaId": "DA778424-6F70-4AB6-ADD5-5D4664DFE463" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*", "matchCriteriaId": "4D3B5E4F-56A6-4696-BBB4-19DF3613D020" } ] } ] } ], "references": [ { "url": "http://securityreason.com/securityalert/3373", "source": "secure@microsoft.com" }, { "url": "http://www.kb.cert.org/vuls/id/484649", "source": "secure@microsoft.com", "tags": [ "US Government Resource" ] }, { "url": "http://www.scanit.be/advisory-2007-11-14.html", "source": "secure@microsoft.com" }, { "url": "http://www.securityfocus.com/archive/1/483635/100/0/threaded", "source": "secure@microsoft.com" }, { "url": "http://www.securityfocus.com/archive/1/483698/100/0/threaded", "source": "secure@microsoft.com" }, { "url": "http://www.securityfocus.com/archive/1/484186/100/0/threaded", "source": "secure@microsoft.com" }, { "url": "http://www.securityfocus.com/bid/25919", "source": "secure@microsoft.com", "tags": [ "Exploit", "Patch" ] }, { "url": "http://www.securitytracker.com/id?1018942", "source": "secure@microsoft.com" }, { "url": "http://www.trusteer.com/docs/windowsdns.html", "source": "secure@microsoft.com" }, { "url": "http://www.us-cert.gov/cas/techalerts/TA07-317A.html", "source": "secure@microsoft.com", "tags": [ "US Government Resource" ] }, { "url": "http://www.vupen.com/english/advisories/2007/3848", "source": "secure@microsoft.com" }, { "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062", "source": "secure@microsoft.com" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36805", "source": "secure@microsoft.com" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395", "source": "secure@microsoft.com" } ] }