PT-2006-2026 · Microsoft · Windows Nt 4.0+3

Published

2006-03-03

·

Updated

2018-10-18

·

CVE-2006-0988

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows Server 2003 (affected versions not specified) Windows 2000 (affected versions not specified) Windows NT 4.0 (affected versions not specified)
Description The default configuration of the DNS Server service allows recursive queries and provides additional delegation information to arbitrary IP addresses. This allows remote attackers to cause a denial of service via DNS queries with spoofed source IP addresses, resulting in traffic amplification.
Recommendations For Windows Server 2003, consider disabling recursive queries to prevent traffic amplification. For Windows 2000, restrict access to the DNS Server service to minimize the risk of exploitation. For Windows NT 4.0, limit the delegation information provided by the Microsoft DNS Server service to reduce the impact of spoofed DNS queries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0988

Affected Products

Dns Server
Windows 2000
Windows Nt 4.0
Windows Server 2003