PT-2000-1997 · Microsoft · Windows 98+3

CVE-2000-1218

·

Publicado

2000-04-14

·

Atualizado

2024-02-08

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 98, NT 4.0, 2000, and XP
Description The default configuration for the domain name resolver sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, allowing remote attackers to poison the DNS cache.
Recommendations For Microsoft Windows 98, NT 4.0, 2000, and XP, consider changing the default configuration of the domain name resolver to set the QueryIpMatching parameter to 1 to prevent DNS cache poisoning. As a temporary workaround, restrict DNS updates to only come from trusted sources until a more permanent solution can be applied.

Correção

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2000-1218

Produtos afetados

Windows 2000
Windows 98
Windows Nt 4.0
Windows Xp