vendor:
Windows Network Stack
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Windows Network Stack
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Denial of Service Vulnerability in Microsoft Windows Network Stack
A potential denial of service vulnerability exists in some versions of the Microsoft Windows network stack. The problem occurs when a large number of extraneous ARP packets sent to a host running Windows. This can cause the system to use all available CPU and memory resources and thus become unresponsive until the attack ends. By sending ARP requests to the Ethernet broadcast address, it may be possible to use this attack to disable an entire network.
Mitigation:
Ensure that the system is running the latest version of Windows and that all security patches have been applied.