CVE-2007-2999
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers…
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
- CVSS 2.0
- 1.8 LOWAV:A/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2003 server
- Source
- cve@mitre.org
References
- http://osvdb.org/36138
- http://secunia.com/advisories/25457Vendor Advisory
- http://www.notsosecure.com/folder2/2007/05/27/logon-time-restrictions-in-a-domain-in-windows-server-2003-allows-username-enumeration/
- http://www.securityfocus.com/bid/24248
- http://osvdb.org/36138
- http://secunia.com/advisories/25457Vendor Advisory
- http://www.notsosecure.com/folder2/2007/05/27/logon-time-restrictions-in-a-domain-in-windows-server-2003-allows-username-enumeration/
- http://www.securityfocus.com/bid/24248
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.