Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
BID:7788
Info
Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
| Bugtraq ID: | 7788 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2003 12:00AM |
| Updated: | Jun 02 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
Microsoft Windows 2000/XP/2003 has been reported prone to a remote denial of service vulnerability.
Reportedly, an attacker may trigger this vulnerability, under certain configurations. Specifcally IPV6 must be enabled on the target server. Under these conditions an attacker may launch an ICMP flood attack, that could effectively deny network services to valid users.
Reportedly this issue is further exaggerated by bid 7666.
Microsoft Windows 2000/XP/2003 has been reported prone to a remote denial of service vulnerability.
Reportedly, an attacker may trigger this vulnerability, under certain configurations. Specifcally IPV6 must be enabled on the target server. Under these conditions an attacker may launch an ICMP flood attack, that could effectively deny network services to valid users.
Reportedly this issue is further exaggerated by bid 7666.
Exploit / POC
Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.