CVE-2007-1533
The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports within a solicitation session, which makes it easier for remote attackers to spoof the nonce through brute force attacks.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports within a solicitation session, which makes it easier for remote attackers to spoof the nonce through brute force attacks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 10.62% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows vista
- Source
- cve@mitre.org
References
- http://osvdb.org/33666
- http://www.securityfocus.com/archive/1/462793/100/0/threaded
- http://www.securityfocus.com/archive/1/464617/100/0/threaded
- http://www.securityfocus.com/bid/23301
- http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf
- http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html
- http://osvdb.org/33666
- http://www.securityfocus.com/archive/1/462793/100/0/threaded
- http://www.securityfocus.com/archive/1/464617/100/0/threaded
- http://www.securityfocus.com/bid/23301
- http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf
- http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.