CVE-2000-0673
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 33.45% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows nt
- Source
- cve@mitre.org
References
- http://www.nai.com/research/covert/advisories/044.asp
- http://www.securityfocus.com/bid/1514Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/1515
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5035
- http://www.nai.com/research/covert/advisories/044.asp
- http://www.securityfocus.com/bid/1514Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/1515
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-047
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5035
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.