The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_server_2008 | Microsoft | * | - (including) |
Windows_server_2008 | Microsoft | - (including) | - (including) |
Windows_server_2008 | Microsoft | –gold (including) | –gold (including) |