The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-07T05:04:47.970Z
Reserved: 2009-03-25T00:00:00
Link: CVE-2009-1138
No data.
Status : Deferred
Published: 2009-06-10T18:00:00.377
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-1138
No data.
OpenCVE Enrichment
No data.
Weaknesses