Junglewise Threat Intelligence

CVE-1999-0294: Microsoft WINS database deletion via SNMP

CVE-1999-0294 · Severity: medium · CVSS 5 · Published 1997-10-01

Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Internet Name Service (WINS) allows an attacker to remotely delete all records in the name resolution database. WINS is a legacy service used to map computer names to IP addresses on a network. If exploited, this would cause a significant service outage, preventing computers and users from finding and connecting to servers or other resources on the corporate network.

Technical details

The Windows Internet Name Service (WINS) contains a vulnerability where the database records can be remotely deleted via the Simple Network Management Protocol (SNMP). This issue stems from improper access controls or input validation within the SNMP management interface for WINS. An unauthenticated attacker with network access to the SNMP port can issue commands to purge the entire database, leading to a complete denial of service for NetBIOS name resolution. This effectively breaks network connectivity for legacy Windows environments that rely on WINS for resource location.

Affected products

  • Microsoft Windows Internet Name Service (WINS)

Timeline

  • 1997-10-01: disclosed

References