Описание
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
Ссылки
- Mailing ListThird Party Advisory
- Broken LinkThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkPatchThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkThird Party AdvisoryUS Government Resource
- Broken Link
- PatchVendor Advisory
- Broken LinkThird Party Advisory
- Mailing ListThird Party Advisory
- Broken LinkThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkPatchThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkThird Party AdvisoryUS Government Resource
- Broken Link
- PatchVendor Advisory
- Broken LinkThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:-:*:*:professional:*:x64:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*
EPSS
Процентиль: 98%
0.56873
Средний
7.5 High
CVSS3
8.8 High
CVSS2
Дефекты
CWE-330
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
EPSS
Процентиль: 98%
0.56873
Средний
7.5 High
CVSS3
8.8 High
CVSS2
Дефекты
CWE-330