Lucene search

K
cveMitreCVE-1999-1593
HistoryJan 15, 2009 - 1:30 a.m.

CVE-1999-1593

2009-01-1501:30:00
CWE-59
mitre
web.nvd.nist.gov
62
cve-1999-1593
wins
remote attack
credential theft
denial of service
windows.

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0.024

Percentile

90.0%

Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.

Affected configurations

Nvd
Node
microsoftwindows_2000Match-
OR
microsoftwindows_95Match-
OR
microsoftwindows_98Match-
VendorProductVersionCPE
microsoftwindows_2000-cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
microsoftwindows_95-cpe:2.3:o:microsoft:windows_95:-:*:*:*:*:*:*:*
microsoftwindows_98-cpe:2.3:o:microsoft:windows_98:-:*:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0.024

Percentile

90.0%

Related for CVE-1999-1593