Junglewise Threat Intelligence

CVE-1999-1463: Microsoft Windows NT IP stack improper fragment reassembly

CVE-1999-1463 · Severity: medium · CVSS 5 · Published 1997-07-10

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A vulnerability in the networking component of Windows NT 4.0 allows remote attackers to disrupt system operations or bypass security filters. By sending specially crafted network traffic, an attacker can cause the system to crash or potentially sneak unauthorized data past a firewall. This could lead to unplanned downtime or a breach of network security policies.

Technical details

A vulnerability exists in the TCP/IP stack of Windows NT 4.0 (prior to SP3) related to the handling of fragmented IP packets. The stack incorrectly reassembles sessions when receiving fragmented packets that lack the initial fragment, potentially treating them as a valid session. This flaw can be exploited by a remote, unauthenticated attacker to bypass firewall rules that rely on fragment inspection or to trigger a system crash (Denial of Service). The issue was addressed in Windows NT 4.0 Service Pack 3.

Affected products

  • Microsoft Windows NT 4.0 before Service Pack 3

Timeline

  • 1997-07-10: disclosed

References

Related threats