CVE-1999-0285: Critical severity Microsoft Windows NT vulnerability
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Windows NT Resource Kit telnetfrom your environment.Uninstall or remove the telnet component from the Windows NT Resource Kit on systems where it is not required.
- Configuration
Disable the telnet service/daemon from the Windows NT Resource Kit on affected hosts to prevent exploitation by rapid open-and-close connections.
Windows NT Resource Kit telnet telnet service = disabled - Compensating control
Block or filter TCP port 23 (Telnet) at network perimeter firewalls/ACLs or restrict Telnet access to trusted management networks/IP addresses to mitigate remote exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0285?
CVE-1999-0285 is classified as a Denial of Service vulnerability.
How do I fix CVE-1999-0285?
To mitigate CVE-1999-0285, ensure that the Windows NT Resource Kit is updated to the latest available version.
What software is affected by CVE-1999-0285?
CVE-1999-0285 affects Microsoft Windows NT systems when using the telnet service.
What type of attack does CVE-1999-0285 describe?
CVE-1999-0285 describes an attack that involves opening and immediately closing a telnet connection to cause a denial of service.
Is CVE-1999-0285 still relevant today?
While CVE-1999-0285 is an older vulnerability, it may still be relevant for legacy systems running Windows NT.