PT-2014-1183 · Microsoft · Windows Server 2008 R2+2
Pawel Wylecial
·
Published
2014-05-14
·
Updated
2018-10-12
·
CVE-2014-0256
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2008 SP2
Microsoft Windows Server 2008 R2 SP1
Microsoft Windows Server 2012 Gold
Description
The issue is related to errors in processing iSCSI connections, which can be exploited to cause a denial of service. This can be achieved by sending many crafted packets, resulting in an iSCSI service outage.
Recommendations
For Microsoft Windows Server 2008 SP2, update the iSCSI service to prevent denial of service attacks.
For Microsoft Windows Server 2008 R2 SP1, restrict access to the iSCSI target service until a patch is available.
For Microsoft Windows Server 2012 Gold, consider disabling the iSCSI target service as a temporary workaround until a fix is provided.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008 R2 Sp1
Windows Server 2008 R2
Windows Server 2012