PT-2009-5947 · Microsoft · Windows 2000+3

Published

2009-12-09

·

Updated

2018-10-30

·

CVE-2009-3675

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 2000 SP4, XP SP2, XP SP3, and Server 2003 SP2
Description A denial of service issue exists due to the improper handling of specially crafted ISAKMP messages by the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows. This can be exploited via a malformed ISAKMP request over IPsec, allowing remote authenticated users to cause a denial of service through CPU consumption.
Recommendations For Microsoft Windows 2000 SP4, XP SP2, XP SP3, and Server 2003 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3675

Affected Products

Windows
Windows 2000
Windows Server 2003
Windows Xp