vendor:
Windows NT
by:
7.5
CVSS
HIGH
Remote WINS Record Deletion
CWE
Product Name: Windows NT
Affected Version From: Windows NT Server 4.0
Affected Version To: Windows NT Server 4.0 Terminal Server Edition
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_nt:4.0
Platforms Tested: Windows NT
Windows NT SNMP Service Remote WINS Record Deletion
The SNMP service provided with NT Server 4.0 and NT Server 4.0 Terminal Server Edition allow a remote user to delete WINS records, initiating a denial of service against the network. The attacker must know the SNMP community name and be able to access the SNMP service. Regular access control functions are bypassed by the SNMP function, and SNMP community names are often left at their default values (e.g., 'public').
Mitigation:
Ensure SNMP community names are not left at their default values. Restrict access to the SNMP service and use strong authentication mechanisms. Regularly update and patch the SNMP service.