Vulnerability Details CVE-2007-2999
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.3%
CVSS Severity
CVSS v2 Score 1.8
Products affected by CVE-2007-2999
-
cpe:2.3:o:microsoft:windows_2003_server:gold
-
cpe:2.3:o:microsoft:windows_2003_server:sp1
-
cpe:2.3:o:microsoft:windows_2003_server:sp2