Microsoft Windows ARP Request Denial of Service Vulnerability
BID:25066
Info
Microsoft Windows ARP Request Denial of Service Vulnerability
| Bugtraq ID: | 25066 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2007 12:00AM |
| Updated: | Jul 27 2007 10:15PM |
| Credit: | Knud Erik Højgaard <[email protected]> discovered this issue. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Gold 0 Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows Vista December CTP Microsoft Windows Vista Ultimate Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise Microsoft Windows Vista Business Microsoft Windows Vista beta 2 Microsoft Windows Vista Beta 1 Microsoft Windows Vista Beta Microsoft Windows Vista 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows ARP Request Denial of Service Vulnerability
Microsoft Windows is prone to a denial-of-service vulnerability due to its inefficient handling of malicious ARP requests.
Attackers can exploit this issue to consume excessive CPU resources, denying service to legitimate users for the duration of the attack.
Microsoft Windows XP SP2 and Vista are vulnerable to this issue; other Microsoft operating systems and versions may also be affected.
Microsoft Windows is prone to a denial-of-service vulnerability due to its inefficient handling of malicious ARP requests.
Attackers can exploit this issue to consume excessive CPU resources, denying service to legitimate users for the duration of the attack.
Microsoft Windows XP SP2 and Vista are vulnerable to this issue; other Microsoft operating systems and versions may also be affected.
Exploit / POC
Microsoft Windows ARP Request Denial of Service Vulnerability
An attacker may exploit this issue using readily available network tools.
The following proof of concept is available:
An attacker may exploit this issue using readily available network tools.
The following proof of concept is available:
Solution / Fix
Microsoft Windows ARP Request Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Windows ARP Request Denial of Service Vulnerability
References:
References:
- [Full-disclosure] windows arp dos (Knud Erik Højgaard)
- Microsoft Homepage (Microsoft)