CVE-2007-1644
Microsoft DNS Server - Dynamic DNS Update/Change
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
El mecanismo de actualización DNS en el servidor DNS de Microsoft Windows no valida adecuadamente a clientes en ciertos despliegues o configuraciones, lo cual permite a atacantes remotos cambiar registros de DNS para un servidor web proxy y conducir ataque de "hombre en medio" (man-in-the-middle) sobre el trafico web, llevando a cabo ataques de pharming a través del envenenamiento de registros DNS, y provocar denegación de servicio (error de resolución de nombre).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-03-23 CVE Reserved
- 2007-03-24 CVE Published
- 2024-05-19 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://osvdb.org/43603 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33473 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/3544 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | All Windows Search vendor "Microsoft" for product "All Windows" | abstract_cpe Search vendor "Microsoft" for product "All Windows" and version "abstract_cpe" | - |
Affected
|