CVE-2009-1138
CVSS Score Not Available
58.55%
MEDIUM RiskEPSS (98th percentile)
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
Published: 6/10/2009
Modified: 4/9/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
58.55%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 58.55% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.