NT IOCTL Console DoS Vulnerability
BID:517
Info
NT IOCTL Console DoS Vulnerability
| Bugtraq ID: | 517 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 06 1999 12:00AM |
| Updated: | Jul 06 1999 12:00AM |
| Credit: | Microsoft Security Bulletin (MS99-024) released June 6, 1999. Originally reported to Microsoft by Mark Russinovich of Systems Internals <[email protected]> . |
| Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT IOCTL Console DoS Vulnerability
In Windows NT, device driver services are requested through objects known as IOCTLs. The keyboard and mouse IOCTLs can be invoked by user-level programs. By using specific, legitimate calls malicious code could disable the keyboard and mouse, forcing a reboot to re-establish their usability. On NT Terminal Server, the keyboard and mouse on the remote server could be disabled, forcing a reboot of that machine.
In Windows NT, device driver services are requested through objects known as IOCTLs. The keyboard and mouse IOCTLs can be invoked by user-level programs. By using specific, legitimate calls malicious code could disable the keyboard and mouse, forcing a reboot to re-establish their usability. On NT Terminal Server, the keyboard and mouse on the remote server could be disabled, forcing a reboot of that machine.