CVE-1999-1127Missing Release of Resource after Effective Lifetime in Microsoft Windows NT

Severity
7.5HIGHNVD
EPSS
30.0%
top 3.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fjjp-8g8w-55f2: Windows NT 42022-04-30
CVEList
CVE-1999-1127: Windows NT 42002-03-09