CVE-2008-4023
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 39%
exploitation probability
39%top 1% of all CVEs
observed exploitation
nono source reports it
Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
Affected products
n/a · n/aReferences
http://marc.info/?l=bugtraq&m=122479227205998&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-060http://secunia.com/advisories/32242https://exchange.xforce.ibmcloud.com/vulnerabilities/45585https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6107http://www.securityfocus.com/bid/31609http://www.securitytracker.com/id?1021042http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlhttp://www.vupen.com/english/advisories/2008/2811