vendor:
Windows 2000
by:
jimmers@yandex.ru
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Windows 2000
Affected Version From: 2.21.00
Affected Version To: 2.21.00
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:windows_2000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Winsock RSHD/NT CPU Overusage Denial of Service Vulnerability
Winsock RSHD/NT is a Remote Shell Daemon for Windows NT and Windows 2000. It uses the standard Unix rsh and rcp commands. Upon connecting to the daemon, rsh will supply a port number for the daemon to send standard error data. If the port number specified is invalid, Winsock RSHD/NT will attempt to connect to the invalid port and all port numbers below 1024 (including negative port numbers). Potentially consuming CPU resources and leading to a denial of service.
Mitigation:
Ensure that the port number specified is valid.