CVE-2011-0040 describes a denial-of-service vulnerability in Microsoft Active Directory on Windows Server 2003 SP2. Attackers can exploit this by sending a crafted request for a Service Principal Name (SPN) update, leading to name collisions and potentially causing an authentication downgrade or outage. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having a low attack complexity, but only resulting in partial availability impact. While the EPSS score indicates a higher than average exploitability probability, there is no known exploit code in Metasploit or ExploitDB, and it is not listed on the KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.