CVE Database
/

CVE-2007-2228

Back to search

CVE-2007-2228

Published: Oct 9, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.

VendorProductVersions

n/a

n/a

affected
n/a

References

27153
third-party-advisory
x_refsource_SECUNIA
1018787
vdb-entry
x_refsource_SECTRACK
25974
vdb-entry
x_refsource_BID
HPSBST02280
vendor-advisory
x_refsource_HP
SSRT071480
vendor-advisory
x_refsource_HP
27134
third-party-advisory
x_refsource_SECUNIA
MS07-058
vendor-advisory
x_refsource_MS
ADV-2007-3438
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:2310
vdb-entry
signature
x_refsource_OVAL
TA07-282A
third-party-advisory
x_refsource_CERT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now