Skip to main content

Microsoft Windows Active Directory LSASS Recursive Stack Overflow Vulnerability( 11 November 2009 )

Last Update Date: 28 Jan 2011 Release Date: 11 Nov 2009 5114 Views

RISK: Medium Risk

A denial of service vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008. The vulnerability also exists in implementations of Active Directory Application Mode (ADAM) when installed on Windows XP and Windows Server 2003, and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008. The vulnerability is due to stack space exhaustion during execution of certain types of LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.


Impact

  • Denial of Service

System / Technologies affected

  • Microsoft Windows 2000 Server
  • Windows XP
  • Windows Server 2003
  • Windows Server 2008
  • Active Directory
  • Active Directory Application Mode (ADAM)
  • Active Directory and Active Directory Lightweight Directory Service (AD LDS)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link