CVE-2013-1282
The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 27.01% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/active directory · microsoft/active directory application mode · microsoft/active directory lightweight directory service · microsoft/active directory services
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/ncas/alerts/TA13-100AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-032
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16463
- http://www.us-cert.gov/ncas/alerts/TA13-100AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-032
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16463
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.