Microsoft Active Directory LDAP Server Username Enumeration Weakness
BID:32305
Info
Microsoft Active Directory LDAP Server Username Enumeration Weakness
| Bugtraq ID: | 32305 |
| Class: | Design Error |
| CVE: |
CVE-2008-5112 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | Bernardo Damele Assumpcao Guimaraes - Portcullis Computer Security |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Advanced Server SP4 |
| Not Vulnerable: | |
Discussion
Microsoft Active Directory LDAP Server Username Enumeration Weakness
Microsoft Active Directory is prone to a username-enumeration weakness because of a design error in the application when verifying user-supplied input.
Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
This issue affects Active Directory on these versions of Windows:
Windows 2000 SP4
Windows Server 2003 SP1 and SP2
Other versions may also be affected.
Microsoft Active Directory is prone to a username-enumeration weakness because of a design error in the application when verifying user-supplied input.
Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
This issue affects Active Directory on these versions of Windows:
Windows 2000 SP4
Windows Server 2003 SP1 and SP2
Other versions may also be affected.
Exploit / POC
Microsoft Active Directory LDAP Server Username Enumeration Weakness
An attacker may use the Microsoft Windows Active Directory logon interface to exploit this issue.
The following exploit is available:
An attacker may use the Microsoft Windows Active Directory logon interface to exploit this issue.
The following exploit is available:
Solution / Fix
Microsoft Active Directory LDAP Server Username Enumeration Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Active Directory LDAP Server Username Enumeration Weakness
References:
References:
- Microsoft Windows Active Directory LDAP Server Information Disclosure Vulnerabil (Portcullis)
- Vendor Home Page (Microsoft)