Microsoft Windows Domain Controller LDAP Service Abandon Request Recursion Denial of Service

Strike ID:
E09-06600
CVSS:
7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)
False Positive:
f
Variants:
1
Year:
2009

Description

This strike exploits a vulnerability in the LSASS service by sending an LDAP request followed by a large number of abandon request messages. This causes the function that processes requests to recursively call itself, eventually exhausting the memory available for the stack. Once stack space is exhausted, the LSASS service dies, causing the system to reboot.

CVE