Vulnerability record · CVE-2008-0927 · published 14 April 2008
CVE-2008-0927: Novell eDirectory dhost.exe HTTP Connection header CPU exhaustion DoS
Microsoft · Windows Nt
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 mishandles HTTP Connection headers, allowing a remote attacker to exhaust CPU by sending a request with multiple Connection headers or a Connection header containing multiple comma-separated values. The flaw is a resource-consumption denial of service against the directory service, and the record notes it may be similar to CVE-2008-1777.
Description
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityUnauthenticated remote availability impact with public exploit code and high EPSS, but limited to denial of service and affecting an old, likely legacy product.
What it is
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 mishandles HTTP Connection headers, allowing a remote attacker to exhaust CPU by sending a request with multiple Connection headers or a Connection header containing multiple comma-separated values. The flaw is a resource-consumption denial of service against the directory service, and the record notes it may be similar to CVE-2008-1777.
Impact
An unauthenticated remote attacker can drive sustained CPU consumption on the eDirectory host, degrading or denying directory and authentication services to legitimate users. No confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via HTTP requests to the eDirectory dhost.exe service, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.7005, 99.3rd percentile) and an Exploit-DB entry (5547) exists, indicating public exploit code is available.
What to do
- Upgrade Novell eDirectory 8.7.3 to SP10 or later, or 8.8.2 to a fixed build, per the Novell vendor advisory.
- Restrict network access to the eDirectory HTTP/dhost service to trusted management networks only.
- Rate-limit or filter HTTP requests containing repeated or multi-valued Connection headers at the perimeter or reverse proxy.
- Monitor CPU usage on eDirectory hosts and alert on sustained spikes correlated with HTTP traffic.
Detection
- Inspect HTTP request logs for multiple Connection headers or Connection headers with comma-separated values.
- Alert on sustained CPU saturation on eDirectory/dhost.exe hosts.
- Correlate spikes in inbound HTTP requests to the eDirectory service with host CPU metrics.
- Watch for repeated requests from a single source targeting the eDirectory HTTP listener.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0927 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0927), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.