CVE-1999-1291: Medium severity Microsoft Windows NT vulnerability
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Implement network-level anti-spoofing (ingress/egress filtering at network edges) to prevent attackers from sending packets with forged source IP addresses that could be used to spoof TCP resets.
- Compensating control
Configure perimeter and host firewalls/stateful packet filters to drop or block unsolicited TCP RST (and suspicious PSH+ACK) packets from untrusted networks and require packets to match an existing connection state before accepting RSTs.
- Operational
Monitor network and host logs for unexpected or frequent TCP connection resets (RSTs); alert on anomalous reset patterns and investigate/segregate affected systems until mitigations are applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1291?
The severity of CVE-1999-1291 is considered high due to its potential for remote exploitation.
How do I fix CVE-1999-1291?
To fix CVE-1999-1291, it is recommended to upgrade to supported versions of Windows or apply any available patches provided by Microsoft.
Which systems are affected by CVE-1999-1291?
CVE-1999-1291 affects Microsoft Windows 95 and Windows NT 4.0.
What type of attack is possible with CVE-1999-1291?
CVE-1999-1291 allows attackers to reset TCP connections remotely and potentially spoof packets.
Is CVE-1999-1291 still a concern today?
While CVE-1999-1291 primarily affects outdated systems, it remains a concern for legacy systems still in use.