Microsoft Windows Computer Browser Reset Vulnerability

BID:1262

Info

Microsoft Windows Computer Browser Reset Vulnerability

Bugtraq ID: 1262
Class: Design Error
CVE:
Remote: Yes
Local: Yes
Published: May 25 2000 12:00AM
Updated: May 25 2000 12:00AM
Credit: Discovered by Anthony Osborne and publicized in a Network Associates COVERT Labs Advisory (COVERT-2000-05) on May 25, 2000.
Vulnerable: Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Server 4.0 SP6a
+ Avaya DefinityOne Media Servers
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
+ Avaya S8100 Media Servers 0
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Server 4.0 SP4
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Server 4.0
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows 98
Microsoft Windows 95
Microsoft Windows 2000 Server
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Advanced Server
Not Vulnerable:

Discussion

Microsoft Windows Computer Browser Reset Vulnerability

By default, the CIFS browser protocol is publicly available and delivered on the network through UDP port 138. CIFS browser protocol defines a set of browser frames which is decoded by Network Monitor and generated by the "browstat.exe" utility. Due to the implementation within windows there is no capability to configure a browser to ignore ResetBrowser frames. While the CIFS browser protocol is unauthenticated the service is vulnerable to a remote shutdown of the host and user browser service, making it almost impossible for users to locate services and other computers on a network.

Exploit / POC

Microsoft Windows Computer Browser Reset Vulnerability

Currently the SecurityFocus staff are not aware of any exploit for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Microsoft Windows Computer Browser Reset Vulnerability

Solution:
Microsoft has released patches which rectify this issue:


Microsoft Windows 2000 Professional

Microsoft Windows NT Enterprise Server 4.0

Microsoft Windows NT Enterprise Server 4.0 SP2

Microsoft Windows NT Server 4.0 SP3

Microsoft Windows NT Workstation 4.0 SP6a

Microsoft Windows NT Enterprise Server 4.0 SP3

Microsoft Windows NT Workstation 4.0 SP6

Microsoft Windows NT Server 4.0 SP1

Microsoft Windows NT Workstation 4.0 SP5

Microsoft Windows NT Workstation 4.0

Microsoft Windows NT Enterprise Server 4.0 SP4

Microsoft Windows NT Workstation 4.0 SP2

Microsoft Windows NT Enterprise Server 4.0 SP6

Microsoft Windows NT Enterprise Server 4.0 SP5

Microsoft Windows NT Server 4.0

Microsoft Windows NT Workstation 4.0 SP3

Microsoft Windows NT Workstation 4.0 SP4

Microsoft Windows NT Enterprise Server 4.0 SP6a

Microsoft Windows NT Server 4.0 SP6

Microsoft Windows NT Server 4.0 SP6a

Microsoft Windows NT Server 4.0 SP5

Microsoft Windows NT Server 4.0 SP2

Microsoft Windows NT Workstation 4.0 SP1

Microsoft Windows NT Enterprise Server 4.0 SP1

Microsoft Windows 2000 Advanced Server

Microsoft Windows 2000 Server

Microsoft Windows NT Server 4.0 SP4

References

Microsoft Windows Computer Browser Reset Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report