CVE-2007-3898
Summary
| CVE | CVE-2007-3898 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-11-14 01:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 2000 | All | gold | All | All |
| Operating System | Microsoft | Windows 2000 | All | gold | adv_srv | All |
| Operating System | Microsoft | Windows 2000 | All | gold | datacenter_srv | All |
| Operating System | Microsoft | Windows 2000 | All | gold | srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | adv_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | datacenter_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | adv_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | datacenter_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | adv_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | datacenter_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | adv_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | datacenter_srv | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | srv | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | std | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | x64 | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | x64-std | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp1 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp1 | std | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | std | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2003 | All | - | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Windows DNS Service Cache Poisoning Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Microsoft Security Bulletin MS07-062 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#484649 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Microsoft Windows Recursive DNS Spoofing Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM Security Trusteer Fraud Protection Software | IBM | af854a3a-2127-422b-91ae-364da2661108 | www.trusteer.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Microsoft Windows DNS Service Insufficent Entropy Lets Remote Users Spoof the DNS Service | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityReason - Microsoft Windows DNS Service Cache Poisoning Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| US-CERT Technical Cyber Security Alert TA07-317A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Scanit - Predictable DNS transaction IDs in Microsoft DNS Server | af854a3a-2127-422b-91ae-364da2661108 | www.scanit.be | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.