search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft Windows 2000 Telnet Service fails to enforce timeouts on idle telnet sessions

Vulnerability Note VU#855723

Original Release Date: 2001-09-18 | Last Revised: 2001-09-18

Overview

The Microsoft Windows 2000 Telnet Service contains a denial-of-service vulnerability that allows remote attackers to disrupt the telnet service on affected servers.

Description

The Microsoft Windows 2000 Telnet Service contains a vulnerability that allows a remote attacker to place idle telnet sessions in a state that prevents the Telnet Service from enforcing pre-defined timeout values. By establishing a large number of telnet sessions and forcing them to this state, an attacker can consume all available telnet sessions and prevent other users from establishing new telnet sessions.

Impact

This vulnerability allows a remote attacker to consume all available telnet sessions, resulting in a denial-of-service condition.

Solution

Apply a patch from your vendor

Microsoft has released a patch for this vulnerability; for further information, please consult the systems affected section below.

Vendor Information

855723
 

Microsoft Affected

Updated:  September 14, 2001

Status

Affected

Vendor Statement

Microsoft has addressed this vulnerability in the following Microsoft Security Bulletin

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has archived Microsoft's announcement of MS01-031 at


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Jeffrey P. Lanza and is based on information provided by Microsoft.

Other Information

CVE IDs: CVE-2001-0345
Severity Metric: 5.06
Date Public: 2001-06-07
Date First Published: 2001-09-18
Date Last Updated: 2001-09-18 23:27 UTC
Document Revision: 7

Sponsored by CISA.