Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-2228

EPSS 76.75% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-2228

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows RPC认证远程拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Windows系统在处理RPC认证时存在漏洞,远程攻击者可能利用此漏洞导致系统拒绝服务。 漏洞具体存在于RPC运行时库rpcrt4.dll解析RPC级认证消息期间。在解析认证类型为NTLMSSP且认证级别为PACKET的报文时,如果验证尾部签名被初始化为0而不是标准的NTLM签名,就会出现无效的内存引用。成功利用这个漏洞可能导致RPC服务及整个操作系统崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-2228

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-2228

Please Login to view more intelligence information

Same Patch Batch · n/a · 2007-10-09 · 63 CVEs total

CVE-2007-5307ELSEIF CMS 'upload.php' alphanumeric参数多个输入验证漏洞
CVE-2007-3897Microsoft Outlook Express和Windows Mail NNTP协议回应数据缓冲区错误漏洞
CVE-2007-5319Sun Solaris vuidmice STREAMS模数未明拒绝服务漏洞
CVE-2007-4466Electronic Arts SnoopyCtrl ActiveX控件'NPSnpy.dll' 多个缓冲区溢出漏洞
CVE-2007-3899Microsoft Word工作区内存破坏远程代码执行漏洞
CVE-2007-5312TorrentTrader Classic cat参数多个跨站脚本攻击漏洞
CVE-2007-5311TorrentTrader Classic Edition 'backend/admin-functions.php' 目录遍历漏洞
CVE-2007-5310Joomla! Webmaster-Tips.net 'admin.wmtportfolio.php' 远程文件包含漏洞
CVE-2007-5309Joomla! Webmaster-Tips.net Flash Image Gallery 'admin.wmtgallery.php' 远程文件包含漏洞
CVE-2007-5308PHP Homepage M 'galerie.php' SQL注入漏洞
CVE-2007-5313Picturesolution 'Config.PHP' 远程文件包含漏洞
CVE-2007-5306ELSEIF CMS 'votesresultats.php' 多个输入验证漏洞
CVE-2007-5305Else If CMS 多个PHP远程文件包含漏洞
CVE-2007-5304ELSEIF CMS 跨站脚本攻击漏洞
CVE-2007-5303SnewsCMS Rus 'news_page.php' 跨站脚本攻击漏洞
CVE-2007-5302HP System Management Homepage (SMH) for Linux, Windows, and HP-UX 多个跨站脚本攻击漏洞
CVE-2007-5301AlsaPlayer Vorbis输入插件OGG文件处理远程缓冲区溢出漏洞
CVE-2007-5300wzdftpd USER指令远程拒绝服务漏洞
CVE-2007-5299SkaDate Online Dating Software 'member/' 多个目录遍历漏洞
CVE-2007-5298CMS Creamotion 多个PHP远程文件包含漏洞代码注入漏洞

Showing top 20 of 63 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-2228

No comments yet


Leave a comment