PT-2007-2917 · Microsoft · Windows Vista
Published
2007-03-20
·
Updated
2018-10-16
·
CVE-2007-1527
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista
Description
The issue concerns the LLTD Mapper in Microsoft Windows Vista, which fails to verify the validity of an IP address in a specific field of a HELLO packet. This allows remote attackers to deceive users into communicating with an external host by sending a HELLO packet with a spoofed field, leading to a "Spoof and Management URL IP Redirect" attack.
Recommendations
For Microsoft Windows Vista, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows Vista