CVE-1999-1361: Medium severity Microsoft Windows NT vulnerability
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network exposure of WINS servers: place WINS hosts behind a firewall or ACLs so only trusted networks/hosts can send requests, and implement network-level rate limiting or packet filtering at the edge to drop or throttle floods of malformed packets directed at WINS.
- Operational
Recover from resource exhaustion by clearing or archiving filled event logs and restarting the WINS service or the affected server to restore normal operation; enable ongoing monitoring/alerting of event logs and resource usage to detect and respond to recurring floods.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1361?
CVE-1999-1361 is considered a denial of service vulnerability that can lead to resource exhaustion.
How does CVE-1999-1361 exploit Windows NT?
CVE-1999-1361 exploits Windows NT 3.51 and 4.0 by flooding the WINS service with malformed packets.
What services are affected by CVE-1999-1361?
CVE-1999-1361 affects the Windows Internet Name Service (WINS) on Windows NT 3.51 and 4.0.
How can I mitigate the effects of CVE-1999-1361?
To mitigate CVE-1999-1361, consider disabling WINS or implementing network filtering to block malformed packets.
What versions of Windows NT are vulnerable to CVE-1999-1361?
CVE-1999-1361 specifically affects Windows NT versions 3.51 and 4.0.