SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0069

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that…

HIGH 9.3EPSS 49.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 49.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
49.20% probability · 99th percentile
CISA KEV
Not listed
Affected
microsoft/windows 2003 server · microsoft/windows vista · microsoft/windows xp
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.