Vulnerability Name: | CVE-2005-0048 (CCN-19103) | ||||||||||||||||
Assigned: | 2005-02-08 | ||||||||||||||||
Published: | 2005-02-08 | ||||||||||||||||
Updated: | 2019-04-30 | ||||||||||||||||
Summary: | Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability." | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-0048 Source: CCN Type: CIAC INFORMATION BULLETIN P-177 Vulnerabilities in TCP-IP (893066) Source: CCN Type: US-CERT VU#233754 Microsoft Windows does not adequately validate IP options Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#233754 Source: CCN Type: Microsoft Security Bulletin MS05-019 Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial of Service (893066) Source: CCN Type: Microsoft Security Bulletin MS06-032 Vulnerability in TCP/IP Could Allow Remote Code Execution (917953) Source: CCN Type: Microsoft Security Bulletin MS08-001 Vulnerabilities in TCP/IP Could Allow Remote Code Execution (941644) Source: CCN Type: Microsoft Security Bulletin MS08-004 Vulnerability in Windows TCP/IP Could Allow Denial of Service (946456) Source: CCN Type: BID-13116 Microsoft Windows Internet Protocol Validation Remote Code Execution Vulnerability Source: CERT Type: Patch, US Government Resource TA05-102A Source: ISS Type: Vendor Advisory 20050412 Windows IP Options Remote Compromise Source: MS Type: UNKNOWN MS05-019 Source: XF Type: UNKNOWN win-tcp-ip-dos(19103) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1744 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3824 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:4549 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |