CVE-1999-0909

Microsoft Terminal Server - IP Source Routing Bypass via Malformed Packet

Title source: llm
STIX 2.1

Description

Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ238453
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/646

Scores

EPSS 0.1201
EPSS Percentile 95.7%

Details

CWE
CWE-264
Status published
Products (5)
microsoft/terminal_server
microsoft/windows_95 0a
microsoft/windows_95 0b
microsoft/windows_98se
microsoft/windows_nt 4.0 (6 CPE variants)
Published Sep 20, 1999
Tracked Since Feb 18, 2026