Vulnerability record · CVE-2007-1748 · published 13 April 2007
CVE-2007-1748: Microsoft Windows DNS Server Service RPC stack buffer overflow
Microsoft · Windows 2000
The RPC interface of the Windows DNS Server Service contains a stack-based buffer overflow triggered by a long zone name containing escape-sequence character constants. A remote, unauthenticated attacker can send a crafted request to the DNS RPC interface and corrupt memory. The flaw affects Windows 2000 Server SP4 and Windows Server 2003 SP1/SP2.
Description
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0, remote unauthenticated code execution, public exploit code, and very high EPSS make this an urgent patching priority despite no KEV listing.
What it is
The RPC interface of the Windows DNS Server Service contains a stack-based buffer overflow triggered by a long zone name containing escape-sequence character constants. A remote, unauthenticated attacker can send a crafted request to the DNS RPC interface and corrupt memory. The flaw affects Windows 2000 Server SP4 and Windows Server 2003 SP1/SP2.
Impact
Successful exploitation allows arbitrary code execution in the context of the DNS Server Service, which typically runs with high privileges on the domain controller or DNS server. This can lead to full compromise of the affected host.
Attack surface
Reachable over the network through the DNS Server Service RPC interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The attacker only needs network access to the RPC endpoint.
Exploitation
Not listed in CISA KEV, but EPSS is 0.77664 (99.5th percentile) and a public Metasploit module exists, indicating mature, widely available exploit code.
What to do
- Apply Microsoft security bulletin MS07-029 immediately on all affected Windows 2000 Server SP4 and Windows Server 2003 SP1/SP2 systems.
- Restrict network access to the DNS Server Service RPC interface (TCP/UDP 135 and dynamic RPC ports) to trusted management hosts only.
- Disable or remove the DNS Server role on systems that do not require it.
- Monitor Microsoft advisories and US-CERT alerts for any updated guidance or workarounds.
Detection
- Inspect DNS server and RPC logs for unusually long zone names or malformed escape sequences.
- Deploy network signatures for the Metasploit msdns_zonename exploit and similar RPC DNS zone-name payloads.
- Monitor for unexpected process creation or crashes of dns.exe on DNS servers.
- Alert on RPC traffic to the DNS service from untrusted or unusual source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1748 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1748), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.