peter bassill · operator
$ cve CVE-2007-1644 JSON

CVE-2007-1644 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 32.6% (pctl 98)

Patch early

A public exploit exists.

Description

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS32.56% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-24
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftall windows

Public exploits

SourceTitleDate
exploit-dbMicrosoft DNS Server - Dynamic DNS Update/Change2007-03-22

References

→ the Explorer  ·  watch your stack  ·  NVD