PT-1999-1585 · Microsoft · Windows Nt

Published

1999-12-31

·

Updated

2024-02-08

·

CVE-1999-1127

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Windows NT version 4.0
Description The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by establishing a series of connections with malformed data. This is related to the improper shutdown of invalid named pipe RPC connections.
Recommendations For Windows NT version 4.0, consider restricting access to named pipe RPC connections to minimize the risk of exploitation. As a temporary workaround, limiting the number of concurrent connections may help mitigate the issue until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

CVE-1999-1127

Affected Products

Windows Nt