vendor:
NetMeeting
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: NetMeeting
Affected Version From: NT 4.0 / 2000
Affected Version To: NT 4.0 / 2000
Patch Exists: YES
Related CWE: CVE-2000-0753
CPE: //a:microsoft:netmeeting
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2000
NetMeeting Remote Desktop Sharing Denial of Service Vulnerability
The Remote Desktop Sharing component of Microsoft NetMeeting for Windows NT 4.0 / 2000 does not properly handle a particular type of malformed input string sent over port 1720. CPU utilization can be caused to spike to 100% and any existing NetMeeting sessions would fail in the event of an attack. Restarting the application would be required in order to regain normal functionality.
Mitigation:
Install the latest patch.