>> Microsoft Windows Multiple DNS Spoofing Vulnerabilities (MS08-037)
Title : Microsoft Windows Multiple DNS Spoofing Vulnerabilities (MS08-037) VUPEN ID : VUPEN/ADV-2008-2019 CVE ID : CVE-2008-1447 - CVE-2008-1454 CWE ID : CWE-19 - CWE-331 - CWE-346
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-08
Technical Description
Two vulnerabilities have been identified in Microsoft Windows, which could be exploited to conduct spoofing and cache poisoning attacks.
The first issue is caused by an error in the Windows DNS service within the Windows DNS client and DNS server does not provide enough entropy when performing DNS queries, which could allow an attacker to insert arbitrary addresses into the DNS cache and redirect Internet traffic from legitimate locations to a malicious address.
The second vulnerability is caused by an error in the DNS server that accepts records from a response that is outside the remote server's authority, which could allow attackers to insert false or misleading DNS data in the response to specific DNS requests, thereby redirecting Internet traffic.