CVE-2005-1216: High severity Microsoft ISA Server vulnerability
Published Jun 14, 2005
·Updated
Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
Affected Software
1 affected component
Microsoft ISA Server=2000
Remediation
Patch Available
Event History
Jun 14, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1216?
CVE-2005-1216 has a moderate severity level due to potential exploitation via unauthorized NetBIOS connections.
2
How do I fix CVE-2005-1216?
To fix CVE-2005-1216, you should configure the ISA Server to block NetBIOS traffic in accordance with best security practices.
3
What types of attacks are possible with CVE-2005-1216?
Exploitation of CVE-2005-1216 could allow remote attackers to access internal services that utilize the NetBIOS protocol.
4
Is CVE-2005-1216 specific to certain versions of Microsoft ISA Server?
Yes, CVE-2005-1216 specifically affects Microsoft ISA Server 2000.
5
What is the risk of leaving CVE-2005-1216 unpatched?
Leaving CVE-2005-1216 unpatched increases the risk of unauthorized access to sensitive services on the network.