CVE-2008-1440: Input Validation
Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1440?
CVE-2008-1440 is considered a critical vulnerability that may lead to a denial of service.
How do I fix CVE-2008-1440?
To remediate CVE-2008-1440, it is essential to apply the latest security patches provided by Microsoft for the affected systems.
What systems are affected by CVE-2008-1440?
CVE-2008-1440 affects Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP1 and SP2.
Can CVE-2008-1440 be exploited remotely?
Yes, CVE-2008-1440 can be exploited remotely by sending specially crafted PGM packets.
What type of attack does CVE-2008-1440 facilitate?
CVE-2008-1440 facilitates denial of service attacks, potentially causing system hangs or infinite loops.