CVE-1999-1291

Microsoft Windows 95 and Windows NT 4.0 - TCP Connection Reset via Sequence Number Spoofing

Title source: llm
STIX 2.1

Description

TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1383
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/10789

Scores

EPSS 0.1345
EPSS Percentile 96.1%

Details

Status published
Products (2)
microsoft/windows_95
microsoft/windows_nt 4.0
Published Oct 05, 1998
Tracked Since Feb 18, 2026