Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-3880Microsoft Windows 2003 Server vulnerability

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
16.6%
top 5.07%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 27
Latest updateMay 1

Description

Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of th

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jfff-828v-j87f: ** DISPUTED ** Microsoft Windows NT 42022-05-01
CVEList
CVE-2006-3880: Microsoft Windows NT 42006-07-27

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows XP/2000/2003 - Remote Denial of Service2006-07-24
CVE-2006-3880 — Microsoft vulnerability | cvebase