CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 10.0. It affects Microsoft, Windows. Its EPSS score suggests a 39.4% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2009-1138
Severity
HIGH
CVSS
10
EPSS
39.40%
Microsoft Windows
Original NVD Description
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.