CVE-2011-0040

Description

The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka Active Directory SPN Validation Vulnerability.

Risk Information

Base Score
6.0
MODERATE
Vector
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
40.229

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Server 2003 (KB2478953)Windows
Security Update for Windows Server 2003 x64 Edition (KB2478953)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234