CVE-2007-4000

8.5
CVSS v2.0 Base Score
6.14%
LOW RiskEPSS (93rd percentile)

The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.

Published: 9/5/2007
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

8.5

AV:N/AC:M/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

6.14%LOW Exploitation Risk
93rd percentile

This vulnerability has a 6.14% probability of being exploited in the next 30 days, ranking higher than 93% of all scored CVEs.

CWE Classification

Advertisement