Vulnerabilities > CVE-2007-1644 - Denial-Of-Service vulnerability in Microsoft ALL Windows Abstractcpe

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
microsoft
critical
exploit available

Summary

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).

Vulnerable Configurations

Part Description Count
OS
Microsoft
1

Exploit-Db

descriptionMicrosoft DNS Server (Dynamic DNS Updates) Remote Exploit. CVE-2007-1644. Remote exploit for windows platform
fileexploits/windows/remote/3544.c
idEDB-ID:3544
last seen2016-01-31
modified2007-03-22
platformwindows
port
published2007-03-22
reporterAndres Tarasco
sourcehttps://www.exploit-db.com/download/3544/
titleMicrosoft DNS Server - Dynamic DNS Updates Remote Exploit
typeremote