Improper input validation in Windows and Windows Server - CVE-2017-0004
Published: January 10, 2017 / Updated: February 3, 2017
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause denial of service conditions.
The vulnerability exists due to the way the Local Security Authority Subsystem Service (LSASS) handles authentication requests. A remote unauthenticated attacker can send a specially crafted authentication request to vulnerable system and trigger its automatic reboot.
Successful exploitation of the vulnerability will result in denial of service attack.