CVE-2000-1218
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.09% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/458659Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4280Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/458659Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4280Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.