Junglewise Threat Intelligence

CVE-1999-0077: Generic TCP/IP stack predictable sequence number spoofing

CVE-1999-0077 · Severity: medium · CVSS 5 · Published 1995-01-01

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A fundamental weakness in how various operating systems generate network connection identifiers allows attackers to impersonate legitimate users. By predicting these identifiers, an attacker can hijack active sessions or inject malicious data into network traffic. This can lead to unauthorized access to sensitive systems and the compromise of data integrity across the network.

Technical details

The vulnerability stems from a lack of sufficient entropy or randomness in the Initial Sequence Number (ISN) generation algorithm of the TCP/IP stack. A remote attacker can observe existing traffic to predict the sequence numbers of future packets. By successfully guessing these numbers, the attacker can bypass IP-based authentication, inject data into an established TCP stream, or hijack a session without needing to see the response packets. This is a protocol-level design flaw that affected numerous early operating system implementations of the TCP/IP suite.

Affected products

  • Microsoft windows_nt

Timeline

  • 1995-01-01: disclosed: Initial disclosure date recorded in NVD

References

Related threats