PT-2012-4095 · Microsoft · Windows 7+3
Published
2012-10-09
·
Updated
2020-09-28
·
CVE-2012-2551
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2008 R2 and R2 SP1
Microsoft Windows 7 Gold and SP1
Description
A denial of service issue exists due to the improper handling of a specially crafted session by the Microsoft Kerberos implementation. This can cause the system to stop responding and restart when exploited. The issue arises from a crafted session request that leads to a NULL pointer dereference and subsequent system reboot.
Recommendations
For Microsoft Windows Server 2008 R2 and R2 SP1, apply the necessary patch to fix the Kerberos implementation.
For Microsoft Windows 7 Gold and SP1, apply the necessary patch to fix the Kerberos implementation.
As a temporary workaround, consider restricting access to the Kerberos service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kerberos
Windows
Windows 7
Windows Server 2008 R2