PT-2012-4095 · Microsoft · Windows 7+3

Published

2012-10-09

·

Updated

2020-09-28

·

CVE-2012-2551

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2008 R2 and R2 SP1 Microsoft Windows 7 Gold and SP1
Description A denial of service issue exists due to the improper handling of a specially crafted session by the Microsoft Kerberos implementation. This can cause the system to stop responding and restart when exploited. The issue arises from a crafted session request that leads to a NULL pointer dereference and subsequent system reboot.
Recommendations For Microsoft Windows Server 2008 R2 and R2 SP1, apply the necessary patch to fix the Kerberos implementation. For Microsoft Windows 7 Gold and SP1, apply the necessary patch to fix the Kerberos implementation. As a temporary workaround, consider restricting access to the Kerberos service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-2551

Affected Products

Kerberos
Windows
Windows 7
Windows Server 2008 R2