peter bassill · operator
$ cve CVE-2007-1748 JSON

CVE-2007-1748 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 77.7% (pctl 100)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS77.66% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-04-13
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD