First published: Wed Feb 10 2010(Updated: )
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =gold | |
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0242 has a severity rating that indicates it can lead to denial of service conditions.
To fix CVE-2010-0242, you should apply the security updates provided by Microsoft for Windows Vista and Windows Server 2008.
CVE-2010-0242 affects Microsoft Windows Vista and various versions of Windows Server 2008.
The vulnerability in CVE-2010-0242 allows remote attackers to cause a system hang via crafted TCP packets.
Currently, the best approach for CVE-2010-0242 is to implement the available security patches rather than relying on workarounds.