CVE-2009-1926 Information

Description

Microsoft Windows 2000 SP4 XP SP2 and SP3 Server 2003 SP2 Vista Gold SP1 and SP2 and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely aka \TCP/IP Orphaned Connections Vulnerability.\

Reference

http://osvdb.org/57797 http://www.recurity-labs.com/content/pub/Microsoft_Windows_CVE-2009-1926 http://www.securityfocus.com/archive/1/506331/100/0/threaded http://www.securityfocus.com/bid/36269 http://www.us-cert.gov/cas/techalerts/TA09-251A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-048 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A5965

Share on: