Executive Summary

Summary
Title Vulnerability in Active Directory Could Allow Denial of Service (2478953)
Informations
Name MS11-005 First vendor Publication 2011-02-08
Vendor Microsoft Last vendor Modification 2011-02-08
Severity (Vendor) Important Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Revision Note: V1.0 (February 8, 2011): Bulletin published.Summary: This security update resolves a publicly disclosed vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sent a specially crafted packet to an affected Active Directory server. The attacker must have valid local administrator privileges on the domain-joined computer in order to exploit this vulnerability.

Original Source

Url : http://www.microsoft.com/technet/security/bulletin/MS11-005.mspx

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:12485
 
Oval ID: oval:org.mitre.oval:def:12485
Title: Active Directory SPN Validation Vulnerability
Description: The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2011-0040
Version: 4
Platform(s): Microsoft Windows Server 2003
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 3

OpenVAS Exploits

Date Description
2011-02-09 Name : Microsoft Windows Active Directory SPN Denial of Service (2478953)
File : nvt/secpod_ms11-005.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
70825 Microsoft Windows Server Active Directory Server Principal Name (SPN) Handlin...

Microsoft Windows contains a flaw that may allow a local denial of service. The issue is triggered when an error in Active Directory occurs when handling Server Principal Name update requests. This may be exploited by a local authenticated attacker with administrative privileges via crafted packets to the Active Directory server to cause a denial of service.

Information Assurance Vulnerability Management (IAVM)

Date Description
2011-02-10 IAVM : 2011-B-0015 - Microsoft Windows Active Directory Denial of Service Vulnerability
Severity : Category II - VMSKEY : V0026057

Snort® IPS/IDS

Date Description
2014-01-10 Microsoft Windows Server 2003 update service principal name spn dos attempt
RuleID : 18407 - Revision : 8 - Type : FILE-OTHER
2014-01-10 Microsoft Windows Server 2003 update service principal name spn dos executabl...
RuleID : 18406 - Revision : 11 - Type : FILE-OTHER

Nessus® Vulnerability Scanner

Date Description
2011-02-08 Name : The directory service on the remote host is affected by denial of service vul...
File : smb_nt_ms11-005.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2014-02-17 11:46:51
  • Multiple Updates
2014-01-19 21:30:35
  • Multiple Updates
2013-11-11 12:41:21
  • Multiple Updates