CVE-2015-0015
Microsoft Windows Server 2003/2008/2012 DoS via Crafted Username Strings to IAS/NPS
Title source: llmDescription
Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-007
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031532
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/71933
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62148
Scores
EPSS
0.7873
EPSS Percentile
99.5%
Details
CWE
CWE-399
Status
published
Products (5)
microsoft/windows_server_2003
microsoft/windows_server_2008
microsoft/windows_server_2008
r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012
r2
Published
Jan 13, 2015
Tracked Since
Feb 18, 2026