Description
Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/33667
Third Party Advisory x_refsource_misc
http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/462793/100/0/threaded
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/464617/100/0/threaded
Third Party Advisory x_refsource_misc
http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/23267
Scores
EPSS
0.1179
EPSS Percentile
95.7%
Details
Status
published
Products (1)
microsoft/windows_vista
Published
Mar 20, 2007
Tracked Since
Feb 18, 2026