CVE-2007-2999
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/06/2007
Last modified:
09/04/2025
Description
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
Impact
Base Score 2.0
1.80
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/36138
- http://secunia.com/advisories/25457
- http://www.notsosecure.com/folder2/2007/05/27/logon-time-restrictions-in-a-domain-in-windows-server-2003-allows-username-enumeration/
- http://www.securityfocus.com/bid/24248
- http://osvdb.org/36138
- http://secunia.com/advisories/25457
- http://www.notsosecure.com/folder2/2007/05/27/logon-time-restrictions-in-a-domain-in-windows-server-2003-allows-username-enumeration/
- http://www.securityfocus.com/bid/24248