MS07-062: Vulnerability in DNS Could Allow Spoofing (941672)

This script is Copyright (C) 2007-2013 Tenable Network Security, Inc.


Synopsis :

Remote DNS server is vulnerable to spoofing attacks.

Description :

The remote host has the Windows DNS server installed.

There is a flaw in the remote version of this server that could allow an
attacker to spoof DNS responses. By exploiting this flaw, an attacker
may be able to redirect legitimate traffic from other systems that could
allow him to construct more complex attacks.

See also :

http://technet.microsoft.com/en-us/security/bulletin/MS07-062

Solution :

Microsoft has released patches for Windows 2000 and 2003 Server.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.2
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 28184 ()

Bugtraq ID: 25919

CVE ID: CVE-2007-3898