Executive brief
A vulnerability exists in Winpopup, a legacy messaging utility used in older Windows environments to send short text alerts between computers on a local network. An attacker can crash the application by sending a message associated with an excessively long username. This results in a denial of service, preventing users from receiving legitimate administrative or system notifications.
Technical details
A denial of service vulnerability exists in the Microsoft Winpopup utility. The flaw is triggered when the application receives a message where the sender's username exceeds expected length limits, likely causing a buffer overflow or improper input handling that leads to an application crash. The attack can be launched remotely over the network without authentication. Successful exploitation results in the termination of the Winpopup process on the target machine, though it does not appear to grant remote code execution based on available historical data.
Affected products
- Microsoft Windows (Winpopup)
Timeline
- 1997-04-01: disclosed: Initial publication date in NVD