CVE-2009-1138
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
El servicio LDAP en Active Directory en Microsoft Windows 2000 SP4 no habilita correctamente la memoria para las solicitudes LDAP y LDAPS, lo que permite a los atacantes remotos ejecutar código arbitrario a través de una solicitud que utiliza codificación hexadecimal, cuya memoria asociada no es liberada, relacionado con un "DN AttributeValue," o "vulnerabilidad libre inválida de Active Directory." Nota: este problema es probablemente una fuga de memoria.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-25 CVE Reserved
- 2009-06-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=804 | Third Party Advisory | |
http://osvdb.org/54937 | Vdb Entry | |
http://support.avaya.com/elmodocs2/security/ASA-2009-214.htm | X_refsource_confirm | |
http://www.securitytracker.com/id?1022349 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-160A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6180 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/35226 | 2019-04-30 | |
http://www.vupen.com/english/advisories/2009/1537 | 2019-04-30 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35355 | 2019-04-30 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-018 | 2019-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Affected
|