PT-2003-1787 · Microsoft · Windows Server 2003+4

Mike Price

·

Published

2003-09-04

·

Updated

2019-04-30

·

CVE-2003-0661

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Windows NT versions 4.0 Windows 2000 Windows XP Windows Server 2003
Description: The issue allows remote attackers to obtain sensitive information by including random memory in a response to a NetBIOS Name Service (NBNS) query.
Recommendations: For Windows NT 4.0, consider disabling the NetBT Name Service (NBNS) until a patch is available. For Windows 2000, restrict access to the NBNS to minimize the risk of exploitation. For Windows XP, avoid using the NBNS for sensitive operations until the issue is resolved. For Windows Server 2003, consider configuring the server to limit responses to NBNS queries as a temporary workaround.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0661

Affected Products

Netbt
Windows 2000
Windows Nt
Windows Server 2003
Windows Xp