CVE-2015-0015

Microsoft Windows Server 2003/2008/2012 DoS via Crafted Username Strings to IAS/NPS

Title source: llm
STIX 2.1

Description

Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031532
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71933
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62148

Scores

EPSS 0.7873
EPSS Percentile 99.5%

Details

CWE
CWE-399
Status published
Products (5)
microsoft/windows_server_2003
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
Published Jan 13, 2015
Tracked Since Feb 18, 2026