CVE-2001-1452
published 2001-08-31CVE-2001-1452: By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to…
PriorityP425high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
9.38%
94.8th percentile
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_nt | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Origin Validation Error
mitre_cwe·CVSS 9.8
[CRITICAL] CWE-346 Origin Validation Error
CWE-346: Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Access Control, Other. Impact: Gain Privileges or Assume Identity, Varies by Context. An attacker can access any functionality that is inadvertently accessible to the source.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by buil
CWE
Improper Verification of Source of a Communication Channel
mitre_cwe
CWE-940 Improper Verification of Source of a Communication Channel
CWE-940: Improper Verification of Source of a Communication Channel
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
When an attacker can successfully establish a communication channel from an untrusted origin, the attacker may be able to gain privileges and access unexpected functionality.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Access Control, Other. Impact: Gain Privileges or Assume Identity, Varies by Context, Bypass Protection Mechanism. An attacker can access any funct
http://support.microsoft.com/default.aspx?scid=KB%3Ben-us%3Bq241352http://www.kb.cert.org/vuls/id/109475http://www.securityfocus.com/bid/6791https://exchange.xforce.ibmcloud.com/vulnerabilities/3675http://support.microsoft.com/default.aspx?scid=KB%3Ben-us%3Bq241352http://www.kb.cert.org/vuls/id/109475http://www.securityfocus.com/bid/6791https://exchange.xforce.ibmcloud.com/vulnerabilities/3675
2001-08-31
Published