CVE-2009-1928

Description

Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via a malformed (1) LDAP or (2) LDAPS request, aka LSASS Recursive Stack Overflow Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
47.858

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 2000 (KB973037)Windows
Security Update for Windows XP (KB973039) x86 based systemsWindows
Security Update for Windows XP (KB973039) x86 based systems for SP3Windows
Security Update for Windows Server 2003 (KB973037)Windows
Security Update for Windows Server 2003 (KB973039)Windows
Security Update for Windows Server 2008 (KB973037) x86 based systemsWindows
Security Update for Windows Server 2008 (KB973037) x86 based systems for SP2Windows
Security Update for Windows XP x64 Edition (KB973039)Windows
Security Update for Windows Server 2003 x64 Edition (KB973037)Windows
Security Update for Windows Server 2003 x64 Edition (KB973039)Windows
Security Update for Windows Server 2008 x64 Edition (KB973037)Windows
Security Update for Windows Server 2008 x64 Edition (KB973037) for SP2Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-7881Security Update for Windows Server 2003 (KB973037)
PATCH-7882Security Update for Windows Server 2003 (KB973039)
PATCH-7884Security Update for Windows Server 2008 (KB973037)
PATCH-7885Security Update for Windows XP x64 Edition (KB973039)
PATCH-7886Security Update for Windows Server 2003 x64 Edition (KB973037)
PATCH-7887Security Update for Windows Server 2003 x64 Edition (KB973039)
PATCH-7889Security Update for Windows Server 2008 x64 Edition (KB973037)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234