PT-2004-2231 · Microsoft · Windows Nt+3

Publicado

2004-12-23

·

Atualizado

2019-04-30

·

CVE-2004-1305

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Windows NT Windows 2000 through SP4 Windows XP through SP1 Windows 2003
Description: The issue allows remote attackers to cause a denial of service. This can be achieved by setting the frame number to zero, which causes an invalid memory address to be used and leads to a kernel crash. Alternatively, setting the rate number to zero leads to resource exhaustion and hang.
Recommendations: For Windows NT, consider applying configuration changes to restrict access to the ANI capability until a fix is available. For Windows 2000 through SP4, update to a newer service pack to resolve the issue. For Windows XP through SP1, update to a newer service pack to resolve the issue. For Windows 2003, consider restricting access to the ANI capability as a temporary workaround until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1305

Produtos afetados

Windows 2000
Windows 2003
Windows Nt
Windows Xp