CVE-2016-9312: High severity NTP ntp vulnerability
Published Jan 13, 2017
·Updated
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.
Affected Software
4 affected components
NTP ntp<=4.2.8
Microsoft Windows
All of the following
NTP ntp<=4.2.8
Microsoft Windows
Event History
Jan 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9312?
CVE-2016-9312 has a severity rating that indicates a denial of service vulnerability affecting the NTP service on Windows.
2
How do I fix CVE-2016-9312?
To fix CVE-2016-9312, upgrade NTP to version 4.2.8p9 or later.
3
Which versions of NTP are affected by CVE-2016-9312?
NTP versions prior to 4.2.8p9 are affected by CVE-2016-9312.
4
Can CVE-2016-9312 be exploited remotely?
Yes, CVE-2016-9312 can be exploited remotely by sending a large UDP packet.
5
What systems are vulnerable to CVE-2016-9312?
CVE-2016-9312 specifically affects NTP running on Windows operating systems.