Junglewise Threat Intelligence

CVE-1999-0274: Microsoft Windows NT DNS server denial of service via unsolicited response

CVE-1999-0274 · Severity: medium · CVSS 5 · Published 1997-01-01

Vendors: Microsoft.

Executive brief

A vulnerability in the Windows NT DNS server allows an attacker to crash or disrupt the service by sending a specially crafted network packet. The DNS server is responsible for translating human-readable website names into computer-readable addresses; if this service fails, users may be unable to access internal or external network resources. This issue can lead to a denial-of-service condition, impacting business operations and network availability.

Technical details

The Microsoft Windows NT DNS server is vulnerable to a denial-of-service (DoS) attack due to improper handling of unsolicited DNS response packets. An unauthenticated remote attacker can send a malicious DNS packet that contains a response to a query that the server never actually initiated. This unexpected state causes the DNS service to fail or become unresponsive. The attack is carried out over the network and does not require user interaction or prior authentication. This vulnerability is primarily associated with legacy Windows NT environments.

Affected products

  • Microsoft Windows NT DNS Server Windows NT 4.0

Timeline

  • 1997-01-01: disclosed

References

Related threats