PT-2017-10439 · Microsoft · Windows Server 2008+4

Published

2017-05-09

·

Updated

2017-05-25

·

CVE-2017-0171

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Windows Server versions 2008 SP2 through 2016
Description A denial of service issue exists when the system is configured to answer version queries. This allows attackers to affect the system. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Windows Server 2008 SP2, consider disabling the version query response feature until a patch is available. For Windows Server 2008 R2 SP1, restrict access to the DNS server to minimize the risk of exploitation. For Windows Server 2012 Gold and R2, avoid responding to version queries in the DNS server configuration until the issue is resolved. For Windows Server 2016, as a temporary workaround, consider configuring the DNS server to ignore version queries until a fix is provided.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0171

Affected Products

Windows
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2016