Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0004

 

Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0004

Published: January 10, 2017 / Updated: February 3, 2017


Vulnerability identifier: #VU4101
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0004
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause denial of service conditions.

The vulnerability exists due to the way the Local Security Authority Subsystem Service (LSASS) handles authentication requests. A remote unauthenticated attacker can send a specially crafted authentication request to vulnerable system and trigger its automatic reboot.

Successful exploitation of the vulnerability will result in denial of service attack.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-0004

Install updates from vendor's website.



External References

Related Security Bulletins