Denial of Service Vulnerability in Novell eDirectory Software
CVE-2008-0927
Currently unrated
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 April 2008
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 77%
What is CVE-2008-0927?
The vulnerability in Novell eDirectory occurs when dhost.exe does not properly handle HTTP requests containing multiple Connection headers or comma-separated values in a single Connection header. This improper handling allows attackers to cause excessive CPU consumption, leading to service interruptions. By executing specially crafted HTTP requests, malicious users can exploit this vulnerability remotely, effectively disrupting the normal operation of the eDirectory service.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.