CVE Vulnerabilities

CVE-2008-0087

Improper Authentication

Published: Apr 08, 2008 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.8 HIGH
AV:N/AC:M/Au:N/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.

Weakness

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Windows-nt Microsoft xp xp
Windows_2000 Microsoft * *
Windows_2003_server Microsoft * *
Windows_2003_server Microsoft * *
Windows_2003_server Microsoft * *
Windows_2003_server Microsoft * *
Windows_vista Microsoft * *
Windows_vista Microsoft - -

Potential Mitigations

References