Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
BID:20804
Info
Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
| Bugtraq ID: | 20804 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-5614 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Nov 20 2007 09:14PM |
| Credit: | h07 <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
Microsoft Windows is prone to a remote denial-of-service vulnerability because the Server service fails to properly handle unexpected network traffic.
Exploiting this issue may cause affected computers to crash, denying service to legitimate users. Reports indicate that this vulnerability can be used to disable the Windows firewall.
To exploit this issue, an attacker must be able to send malformed network traffic from a network interface located in the LAN side of an affected computer.
Microsoft Windows is prone to a remote denial-of-service vulnerability because the Server service fails to properly handle unexpected network traffic.
Exploiting this issue may cause affected computers to crash, denying service to legitimate users. Reports indicate that this vulnerability can be used to disable the Windows firewall.
To exploit this issue, an attacker must be able to send malformed network traffic from a network interface located in the LAN side of an affected computer.
Exploit / POC
Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
References:
References:
- Internet Connection Sharing Vulnerability Test Results (The Vert Daily Post)
- Microsoft ICS DoS FAQ (Tyler Reguly)
- New Windows attack can kill firewall (NetworkWorld)
- Vendor Home Page (Microsoft)