Vulnerabilities > CVE-2003-0110 - Unspecified vulnerability in Microsoft ISA Server and Proxy Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
microsoft
nessus

Summary

The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.

Vulnerable Configurations

Part Description Count
Application
Microsoft
5

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS03-012.NASL
descriptionA vulnerability in Microsoft Proxy Server 2.0 and ISA Server 2000 allows an attacker to cause a denial of service of the remote Winsock proxy service by sending a specially crafted packet that would cause 100% CPU utilization on the remote host and make it unresponsive.
last seen2020-06-01
modified2020-06-02
plugin id11534
published2003-04-13
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11534
titleMS03-012: Microsoft ISA Server Winsock Proxy DoS (331066)

Oval

accepted2007-11-13T12:01:15.559-05:00
classvulnerability
contributors
  • nameTiffany Bergeron
    organizationThe MITRE Corporation
  • nameJeff Cheng
    organizationOpsware, Inc.
descriptionThe Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
familywindows
idoval:org.mitre.oval:def:406
statusaccepted
submitted2003-12-03T12:00:00.000-04:00
titleMicrosoft Winsock Proxy Service Denial of Service
version3