Junglewise Threat Intelligence

CVE-1999-0275: Microsoft Windows NT DNS server denial of service via port 53 flooding

CVE-1999-0275 · Severity: medium · CVSS 5 · Published 1997-06-10

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows NT DNS service allows an attacker to crash the server by sending a large volume of data to the network port used for domain name resolution. This can result in a denial-of-service condition, preventing users and systems from resolving website names or internal network addresses. This disruption can halt business operations that rely on network connectivity and name resolution.

Technical details

The Windows NT DNS server is vulnerable to a denial of service (DoS) attack. The vulnerability is triggered by sending a large volume of characters to UDP or TCP port 53, which the DNS service fails to handle correctly. An unauthenticated remote attacker can exploit this by flooding the port with malformed or oversized requests, leading to a service crash or hang. This prevents the server from responding to legitimate DNS queries. The issue is categorized as a resource exhaustion or improper input validation flaw within the DNS service component.

Affected products

  • Microsoft Windows NT DNS Server Windows NT 4.0 and earlier

Timeline

  • 1997-06-10: disclosed: Initial publication date

References

Related threats