PT-2010-2042 · Microsoft · Windows Vista+2
Published
2010-02-10
·
Updated
2023-12-07
·
CVE-2010-0242
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista versions Gold, SP1, and SP2
Microsoft Windows Server 2008 versions Gold and SP2
Description
A denial of service issue exists due to an error in TCP/IP processing when handling specially crafted TCP packets with a malformed selective acknowledgement (SACK) value. This allows remote attackers to cause a system hang via crafted packets. An attacker could exploit this by sending a small number of specially crafted packets, causing the affected system to stop responding and automatically restart.
Recommendations
For Microsoft Windows Vista versions Gold, SP1, and SP2: Apply the necessary patch to fix the TCP/IP implementation issue.
For Microsoft Windows Server 2008 versions Gold and SP2: Apply the necessary patch to fix the TCP/IP implementation issue.
As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008
Windows Vista
Windows