Microsoft Windows Active Directory LSASS Recursive Stack Overflow Vulnerability( 11 November 2009 )
RISK: Medium Risk
A denial of service vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008. The vulnerability also exists in implementations of Active Directory Application Mode (ADAM) when installed on Windows XP and Windows Server 2003, and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008. The vulnerability is due to stack space exhaustion during execution of certain types of LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.
Impact
- Denial of Service
System / Technologies affected
- Microsoft Windows 2000 Server
- Windows XP
- Windows Server 2003
- Windows Server 2008
- Active Directory
- Active Directory Application Mode (ADAM)
- Active Directory and Active Directory Lightweight Directory Service (AD LDS)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Windows 2000 Server Service Pack 4
- Active Directory - Windows XP Service Pack 2 and Windows XP Service Pack 3
- Active Directory Application Mode (ADAM) - Windows XP Professional x64 Edition Service Pack 2
- Active Directory Application Mode (ADAM) - Windows Server 2003 Service Pack 2
- Active Directory
- Active Directory Application Mode (ADAM) - Windows Server 2003 x64 Edition Service Pack 2
- Active Directory
- Active Directory Application Mode (ADAM) - Windows Server 2003 with SP2 for Itanium-based Systems
- Active Directory - Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Active Directory and Active Directory Lightweight Directory Service (AD LDS) - Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
- Active Directory and Active Directory Lightweight Directory Service (AD LDS)
Vulnerability Identifier
Source
Related Link
Share with