vendor:
Windows 2000
by:
Preddy
N/A
CVSS
N/A
Buffer overflow on ICMP packets with Loose Source and Record Route IP options
N/A
CWE
Product Name: Windows 2000
Affected Version From: Windows 2000 English Standard/Advanced Service Pack 4 + Update Rollup 1 for Service Pack 4 with NAT server enabled
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2006
Windows TCP/IP source routing poc
A buffer overflow vulnerability exists in Windows 2000 built-in NAT server when routing packets with options 'Loose Source and Record Route' defined by RFC 791 through the server. This can cause a Denial of Service (DoS) condition, system hangs, or instable work. Code execution is potentially possible. Tested configuration: Windows 2000 English Standard/Advanced Service Pack 4 + Update Rollup 1 for Service Pack 4 with NAT server enabled. Windows 2003 is not affected.
Mitigation:
Upgrade to Windows 2003 or later.