The 2007 Pwnie Nominee For Best Server-Side Bug

Microsoft DNS Server RPC interface buffer overflow (CVE-2007-1748)

Discovered by: anonymous

The stack overflow in the RPC interface of the Microsoft DNS Server was discovered by an anonymous researcher and was found in the wild in April 2007. It was the first vulnerability on Windows 2003 SP1 that was remotely exploitable by an unauthenticated user. Exploiting the bug is interesting because you have to bypassing SafeSEH.

(CVE-2007-1748)