Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
BID:50281
Info
Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
| Bugtraq ID: | 50281 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 19 2011 12:00AM |
| Updated: | Apr 19 2013 02:40AM |
| Credit: | IBM Rational Application Security Research Group |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition 2005 SP3 Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP3 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows 98SE Microsoft Windows 98 With Plus! Pack Microsoft Windows 98 Resource Kit 1.0 Microsoft Windows 98 SP1 Microsoft Windows 98 j Microsoft Windows 98 b Microsoft Windows 98 a Microsoft Windows 98 Microsoft Windows 95 SR2 Microsoft Windows 95 SP1 Microsoft Windows 95 j Microsoft Windows 95 Build 490.R6 Microsoft Windows 95 Microsoft Windows 7 XP Mode 0 Microsoft Windows 7 Ultimate 0 Microsoft Windows 7 Starter 0 Microsoft Windows 7 Professional 0 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 Home Premium - Sp1 X64 Microsoft Windows 7 Home Premium - Sp1 X32 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for Itanium-based Systems SP1 Microsoft Windows 7 for Itanium-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Microsoft Windows 7 RC Microsoft Windows 7 beta Microsoft Windows 2000 Terminal Services SP4 Microsoft Windows 2000 Terminal Services SP3 Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Support Tools 5 Microsoft Windows 2000 Server Japanese Edition Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Resource Kit Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 7 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
Microsoft Windows is prone to multiple vulnerabilities that let local attackers poison the DNS cache.
Successfully exploiting this issue will allow attackers to manipulate cache data, which may aid in further attacks.
Microsoft Windows is prone to multiple vulnerabilities that let local attackers poison the DNS cache.
Successfully exploiting this issue will allow attackers to manipulate cache data, which may aid in further attacks.
Exploit / POC
Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
The discoverers of these issues have developed a proof-of-concept. Please see the references for more information.
The discoverers of these issues have developed a proof-of-concept. Please see the references for more information.
Solution / Fix
Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows Local DNS Cache Poisoning Vulnerabilities
References:
References:
- DNS poisoning via Port Exhaustion (watchfire)
- Microsoft Windows Homepage (Microsoft )