NT RPC CPU Utilization Vulnerability
BID:688
Info
NT RPC CPU Utilization Vulnerability
| Bugtraq ID: | 688 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 07 1997 12:00AM |
| Updated: | Feb 07 1997 12:00AM |
| Credit: | |
| Vulnerable: |
Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: |
Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 |
Discussion
NT RPC CPU Utilization Vulnerability
Connecting to TCP port 135 and entering 10 or more random characters will cause the target host's CPU to jump to 100% CPU utilization. The server must be restarted to clear the processor utilization.
Connecting to TCP port 135 and entering 10 or more random characters will cause the target host's CPU to jump to 100% CPU utilization. The server must be restarted to clear the processor utilization.
Exploit / POC
NT RPC CPU Utilization Vulnerability
Connect to the target host's TCP port 135 (Telnet, netcat, etc) and enter 10 or more characters.
Connect to the target host's TCP port 135 (Telnet, netcat, etc) and enter 10 or more characters.
Solution / Fix
NT RPC CPU Utilization Vulnerability
Solution:
Microsoft has released a post SP2 hotfix to correct this problem. It is available at:
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP2/rpc-fix/
This fix has been included in Service Pack 3.
Solution:
Microsoft has released a post SP2 hotfix to correct this problem. It is available at:
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP2/rpc-fix/
This fix has been included in Service Pack 3.
References
NT RPC CPU Utilization Vulnerability
References:
References: