Oval Definition:oval:org.mitre.oval:def:15098
Revision Date:2012-05-07Version:45
Title:DNS Denial of Service Vulnerability
Description:The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2012-0006
Platform(s):Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s):
Definition Synopsis
  • Vulnerable Microsoft Windows Server 2003 x86/x64/ia64 SP2
  • DNS role is enabled (Server 2003)
  • AND Windows Server 2003 x86/x64/ia64 SP2
  • Microsoft Windows Server 2003 SP2 (x86) is installed
  • OR Microsoft Windows Server 2003 SP2 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) SP2 is installed
  • AND The version of Dns.exe is less than 5.2.3790.4957
  • OR Vulnerable Microsoft Windows Server 2008 x86/x64 SP2
  • DNS role is enabled (Server 2008 or later)
  • AND Windows Server 2008 x86/x64 SP2
  • Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed
  • OR Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed
  • AND GDR or LDR Service branch
  • The version of Dns.exe is less than 6.0.6002.18557
  • OR LDR
  • The version of Dns.exe is greater than or equal to 6.0.6002.22000
  • AND The version of Dns.exe is less than 6.0.6002.22763
  • OR Vulnerable Microsoft Windows Server 2008 R2 x64
  • DNS role is enabled (Server 2008 or later)
  • AND Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND GDR or LDR Service branch
  • The version of Dns.exe is less than 6.1.7600.16936
  • OR LDR
  • The version of Dns.exe is greater than or equal to 6.1.7600.20000
  • AND The version of Dns.exe is less than 6.1.7600.21114
  • OR Vulnerable Microsoft Windows Server 2008 R2 x64 SP1
  • DNS role is enabled (Server 2008 or later)
  • AND Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed
  • AND GDR or LDR Service branch
  • The version of Dns.exe is less than 6.1.7601.17750
  • OR LDR
  • The version of Dns.exe is greater than or equal to 6.1.7601.21000
  • AND The version of Dns.exe is less than 6.1.7601.21885
  • BACK