PT-2012-4095 · Microsoft · Windows 7+3
Publicado
2012-10-09
·
Atualizado
2020-09-28
·
CVE-2012-2551
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2008 R2 and R2 SP1
Microsoft Windows 7 Gold and SP1
Description
A denial of service issue exists due to the improper handling of a specially crafted session by the Microsoft Kerberos implementation. This can cause the system to stop responding and restart when exploited. The issue arises from a crafted session request that leads to a NULL pointer dereference and subsequent system reboot.
Recommendations
For Microsoft Windows Server 2008 R2 and R2 SP1, apply the necessary patch to fix the Kerberos implementation.
For Microsoft Windows 7 Gold and SP1, apply the necessary patch to fix the Kerberos implementation.
As a temporary workaround, consider restricting access to the Kerberos service to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kerberos
Windows
Windows 7
Windows Server 2008 R2