CVE-2006-0988

Microsoft Windows 2000 - Denial of Service

Title source: rule
STIX 2.1

Description

The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

Exploits (1)

metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/dns/dns_amp.rb

References (3)

Core 3
Core References
Various Sources x_refsource_misc
http://dns.measurement-factory.com/surveys/sum1.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/426368/100/0/threaded
Patch, Vendor Advisory x_refsource_misc
http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf

Scores

EPSS 0.6710
EPSS Percentile 98.6%

Details

Status published
Products (3)
microsoft/windows_2000
microsoft/windows_2003_server r2
microsoft/windows_nt 4.0
Published Mar 03, 2006
Tracked Since Feb 18, 2026