A problem has been discovered in Microsoft Metadirectory Services (MMS) that could allow a user of an LDAP client to gain administrative access. MMS allows a remote user with an LDAP client to change data on a vulnerable server. A flaw in authentication design allows the user of the LDAP client to connect to the MMS repository, modify data, change the MMS configuration, and/or replicate the bogus data in other repositories.
A problem has been discovered in Microsoft Metadirectory Services (MMS) that could allow a user of an LDAP client to gain administrative access. MMS allows a remote user with an LDAP client to change data on a vulnerable server. A flaw in authentication design allows the user of the LDAP client to connect to the MMS repository, modify data, change the MMS configuration, and/or replicate the bogus data in other repositories.