CVE-2007-3898

Scores

EPSS

0.864high86.4%
0%20%40%60%80%100%

Percentile: 86.4%

CVSS

6.4medium2.0
0246810

CVSS Score: 6.4/10

All CVSS Scores

CVSS 2.0
6.4

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Description

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-16

Exploits

Exploit ID: 30635

Source: exploitdb

URL: https://www.exploit-db.com/exploits/30635

Exploit ID: 30636

Source: exploitdb

URL: https://www.exploit-db.com/exploits/30636

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: windows_2000

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:adv_s...

Source: nvd

Type: Configuration

Vendor: *

Product: windows_2003_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:adv_s...

Source: nvd

Type: Configuration

Vendor: *

Product: windows_server_2003

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows_2000:*:gold:adv_s...

Source: nvd

End of list