Vulnerability Name: | CVE-1999-1593 (CCN-5958) | ||||||||
Assigned: | 1999-03-02 | ||||||||
Published: | 1999-03-02 | ||||||||
Updated: | 2020-01-10 | ||||||||
Summary: | Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. Note: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:UR)
4.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-59 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Jan 17 2001 - 15:35:49 CST Invalid WINS entries Source: CCN Type: NTBugTraq Mailing List, Tue, 2 Mar 1999 16:43:10 -0600 NT Domain DoS and Security Exploit with SAMBA Server Source: NTBUGTRAQ Type: Broken Link, Third Party Advisory 19990302 NT Domain DoS and Security Exploit with SAMBA Server Source: MITRE Type: CNA CVE-1999-1593 Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010117 Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010117 Re: Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010118 Re: Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010117 Re: Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010117 Re: Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010118 Re: Invalid WINS entries Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20010119 Re: Invalid WINS entries Source: CCN Type: OSVDB ID: 53309 Microsoft Windows WINS 1Ch Registration Domain Controller Manipulation Source: CCN Type: SANS Institute Reading Room Web site Windows 2000 Know Vulnerabilities and Their Fixes Source: BID Type: Third Party Advisory, VDB Entry 2221 Source: CCN Type: BID-2221 Microsoft WINS Domain Controller Spoofing Vulnerability Source: XF Type: UNKNOWN wins-improper-verification-dos(5958) Source: MISC Type: Broken Link, Exploit https://www2.sans.org/reading_room/whitepapers/win2k/185.php | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |