CVE-1999-0153: Medium severity Microsoft Windows 2000 vulnerability
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable NetBIOS/NetBIOS over TCP/IP on affected Windows systems if it is not required to prevent out-of-band NETBIOS packets (WinNuke) from reaching the host.
Microsoft Windows (NetBIOS) NetBIOS over TCP/IP = disabled - Compensating control
Block or filter NETBIOS port traffic to affected hosts at the network perimeter (firewall/ACL) to prevent out-of-band NETBIOS packets (WinNuke) from reaching vulnerable systems.
- Operational
Isolate affected systems from untrusted networks until mitigations (network filtering or disabling NetBIOS) are applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0153?
CVE-1999-0153 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0153?
To mitigate CVE-1999-0153, disable NETBIOS over TCP/IP if it's not needed.
Which systems are affected by CVE-1999-0153?
CVE-1999-0153 affects Microsoft Windows 95, Windows NT, Windows 2000, and Xinuos OpenServer 5.0.
What type of attack is CVE-1999-0153 associated with?
CVE-1999-0153 is associated with an out of band data attack that causes a denial of service.
Can CVE-1999-0153 be exploited remotely?
Yes, CVE-1999-0153 can be exploited remotely through the NETBIOS port.