PT-2003-1787 · Microsoft · Windows Server 2003+4
Mike Price
·
Published
2003-09-04
·
Updated
2019-04-30
·
CVE-2003-0661
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Windows NT versions 4.0
Windows 2000
Windows XP
Windows Server 2003
Description:
The issue allows remote attackers to obtain sensitive information by including random memory in a response to a NetBIOS Name Service (NBNS) query.
Recommendations:
For Windows NT 4.0, consider disabling the NetBT Name Service (NBNS) until a patch is available.
For Windows 2000, restrict access to the NBNS to minimize the risk of exploitation.
For Windows XP, avoid using the NBNS for sensitive operations until the issue is resolved.
For Windows Server 2003, consider configuring the server to limit responses to NBNS queries as a temporary workaround.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbt
Windows 2000
Windows Nt
Windows Server 2003
Windows Xp