NT CSRSS Worker Thread Exhaustion Vulnerability
BID:478
Info
NT CSRSS Worker Thread Exhaustion Vulnerability
| Bugtraq ID: | 478 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 09 1999 12:00AM |
| Updated: | Apr 09 1999 12:00AM |
| Credit: | Jeff Sumner <[email protected]> discovered this vulnerability and posted it to the newsgroup microsoft.public.win32.programmer.kernel on April 9, 1999. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: |
Microsoft Windows NT 3.5.1 SP5 Microsoft Windows NT 3.5.1 SP4 Microsoft Windows NT 3.5.1 SP3 Microsoft Windows NT 3.5.1 SP2 Microsoft Windows NT 3.5.1 SP1 Microsoft Windows NT 3.5.1 Microsoft Windows NT 3.5 |
Discussion
NT CSRSS Worker Thread Exhaustion Vulnerability
Worker threads in CSRSS.exe (the Client Server Runtime SubSystem, aka the Win32 Subsystem) that are waiting for user input remain occupied until they get that input. If all threads (default 16) are simultaneously waiting for input, the system will hang until it is received. This condition will lead to a Denial of Service, and could be caused by malicious or defective code in a service or program.
Worker threads in CSRSS.exe (the Client Server Runtime SubSystem, aka the Win32 Subsystem) that are waiting for user input remain occupied until they get that input. If all threads (default 16) are simultaneously waiting for input, the system will hang until it is received. This condition will lead to a Denial of Service, and could be caused by malicious or defective code in a service or program.
Exploit / POC
NT CSRSS Worker Thread Exhaustion Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].