PT-2009-1128 · Microsoft · Windows Internet Naming Service
Published
2009-01-15
·
Updated
2020-01-10
·
CVE-1999-1593
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Internet Naming Service (WINS) (affected versions not specified)
Description
The issue allows remote attackers to cause a denial of service, resulting in connectivity loss, or steal credentials by exploiting a registration vulnerability. This is done by using a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. The problem may be limited under certain conditions, such as when using Windows 95/98 clients or if the primary domain controller becomes unavailable.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Internet Naming Service