CVE-2012-0006

Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 - Denial of Service via DNS Record Lookup

Title source: llm
STIX 2.1

Description

The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48394
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52374
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15098
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA12-073A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80005
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026789

Scores

EPSS 0.3108
EPSS Percentile 98.1%

Details

CWE
CWE-399
Status published
Products (3)
microsoft/windows_server_2003
microsoft/windows_server_2008 (2 CPE variants)
microsoft/windows_server_2008 r2
Published Mar 13, 2012
Tracked Since Feb 18, 2026