CVE-2007-0069
Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 49.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 49.20% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2003 server · microsoft/windows vista · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx
- http://secunia.com/advisories/28297Patch, Vendor Advisory
- http://securitytracker.com/id?1019166
- http://www.iss.net/threats/282.html
- http://www.kb.cert.org/vuls/id/115083US Government Resource
- http://www.securityfocus.com/archive/1/486317/100/0/threaded
- http://www.securityfocus.com/bid/27100
- http://www.us-cert.gov/cas/techalerts/TA08-008A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0069Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39453
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5370
- http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx
- http://secunia.com/advisories/28297Patch, Vendor Advisory
- http://securitytracker.com/id?1019166
- http://www.iss.net/threats/282.html
- http://www.kb.cert.org/vuls/id/115083US Government Resource
- http://www.securityfocus.com/archive/1/486317/100/0/threaded
- http://www.securityfocus.com/bid/27100
- http://www.us-cert.gov/cas/techalerts/TA08-008A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0069Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39453
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5370
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.