Executive Summary
| Summary | |
|---|---|
| Title | Vulnerability in DNS Could Allow Spoofing (941672) |
| Informations | |||
|---|---|---|---|
| Name | MS07-062 | First vendor Publication | 2007-11-13 |
| Vendor | Microsoft | Last vendor Modification | 2007-11-13 |
| Severity (Vendor) | Important | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 6.4 | Attack Range | Network |
| Cvss Impact Score | 4.9 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
This important security update resolves a privately reported vulnerability. This spoofing vulnerability exists in Windows DNS Servers and could allow an attacker to send specially crafted responses to DNS requests, thereby spoofing or redirecting Internet traffic from legitimate locations. |
Original Source
| Url : http://www.microsoft.com/technet/security/bulletin/ms07-062.mspx |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-16 | Configuration |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:4395 | |||
| Oval ID: | oval:org.mitre.oval:def:4395 | ||
| Title: | Vulnerability in DNS Could Allow Spoofing | ||
| Description: | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2007-3898 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 41092 | Microsoft Windows DNS Service Predictable Transaction ID Weakness |
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 12:22:04 |
|

MS07-062
(Critical)
(Medium)
(N/A)






