CVE-2012-1194Microsoft Windows Server 2008 vulnerability

2 documents2 sources
Severity
6.4MEDIUMNVD
EPSS
9.7%
top 7.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateMay 17

Description

The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-j28x-whc4-q29c: The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during t2022-05-17