PT-2011-3507 · Microsoft · Windows 7+3
Byoungyoung Lee
·
Published
2011-08-10
·
Updated
2020-09-28
·
CVE-2011-1965
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Microsoft Windows Server versions prior to the fixed version
Description
A denial of service issue exists due to improper handling of URLs in memory when URL-based Quality of Service (QoS) is enabled. This allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server. An attacker who successfully exploits this issue could cause the target system to stop responding and automatically restart.
Recommendations
For Microsoft Windows 7 Gold and SP1, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2008 R2 and R2 SP1, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling URL-based QoS to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows Server
Windows Server 2008 R2