PT-2009-5947 · Microsoft · Windows 2000+3
Published
2009-12-09
·
Updated
2018-10-30
·
CVE-2009-3675
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 2000 SP4, XP SP2, XP SP3, and Server 2003 SP2
Description
A denial of service issue exists due to the improper handling of specially crafted ISAKMP messages by the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows. This can be exploited via a malformed ISAKMP request over IPsec, allowing remote authenticated users to cause a denial of service through CPU consumption.
Recommendations
For Microsoft Windows 2000 SP4, XP SP2, XP SP3, and Server 2003 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 2000
Windows Server 2003
Windows Xp