PT-1999-1585 · Microsoft · Windows Nt
Published
1999-12-31
·
Updated
2024-02-08
·
CVE-1999-1127
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Windows NT version 4.0
Description
The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by establishing a series of connections with malformed data. This is related to the improper shutdown of invalid named pipe RPC connections.
Recommendations
For Windows NT version 4.0, consider restricting access to named pipe RPC connections to minimize the risk of exploitation. As a temporary workaround, limiting the number of concurrent connections may help mitigate the issue until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Nt