PT-2012-4095 · Microsoft · Windows 7+3

Publicado

2012-10-09

·

Atualizado

2020-09-28

·

CVE-2012-2551

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2008 R2 and R2 SP1 Microsoft Windows 7 Gold and SP1
Description A denial of service issue exists due to the improper handling of a specially crafted session by the Microsoft Kerberos implementation. This can cause the system to stop responding and restart when exploited. The issue arises from a crafted session request that leads to a NULL pointer dereference and subsequent system reboot.
Recommendations For Microsoft Windows Server 2008 R2 and R2 SP1, apply the necessary patch to fix the Kerberos implementation. For Microsoft Windows 7 Gold and SP1, apply the necessary patch to fix the Kerberos implementation. As a temporary workaround, consider restricting access to the Kerberos service to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-2551

Produtos afetados

Kerberos
Windows
Windows 7
Windows Server 2008 R2