Junglewise Threat Intelligence

CVE-1999-1581: Microsoft Windows NT SNMP agent memory leak in snmp.exe

CVE-1999-1581 · Severity: medium · CVSS 5 · Published 1997-12-23

Executive brief

A vulnerability exists in the SNMP service of older Windows NT systems, which is used for managing and monitoring devices on a network. By sending a large volume of specially crafted network packets, an attacker can cause the system to run out of memory. This leads to a denial of service, potentially crashing the system or making it unresponsive to legitimate users.

Technical details

A memory leak vulnerability exists in the Microsoft SNMP agent (snmp.exe) in Windows NT 4.0 prior to Service Pack 4. The flaw is triggered when the agent receives SNMP packets containing Object Identifiers (OIDs) that cannot be successfully decoded; in these instances, the application fails to release allocated memory. A remote, unauthenticated attacker can exploit this by flooding the target with malformed SNMP packets, leading to memory exhaustion and a denial of service (DoS) condition. This issue is particularly impactful on network segments with high SNMP broadcast traffic. The vulnerability was addressed in Windows NT 4.0 Service Pack 4.

Affected products

  • Microsoft Windows NT 4.0 before Service Pack 4
  • Microsoft Windows NT Server, Terminal Server Edition before Service Pack 4

Timeline

  • 1997-12-23: disclosed: Initial NVD publication date
  • 1998-03-24: other: Date public according to CERT/CC
  • 1998-04-16: other: Vendor notified
  • 1998-10-25: patched: Windows NT 4.0 Service Pack 4 released

References

Related threats