Vulnerabilities > CVE-2006-5614 - Remote Denial of Service vulnerability in Microsoft Windows NT Helper Components and Windows XP

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available
metasploit

Summary

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1
OS
Microsoft
1

Exploit-Db

descriptionMS Windows NAT Helper Components (ipnathlp.dll) Remote DoS Exploit. CVE-2006-5614. Dos exploit for windows platform
fileexploits/windows/dos/2672.py
idEDB-ID:2672
last seen2016-01-31
modified2006-10-28
platformwindows
port
published2006-10-28
reporterh07
sourcehttps://www.exploit-db.com/download/2672/
titleMicrosoft Windows NAT Helper Components ipnathlp.dll Remote DoS Exploit
typedos

Metasploit

descriptionThis module exploits a denial of service vulnerability within the Internet Connection Sharing service in Windows XP.
idMSF:AUXILIARY/DOS/WINDOWS/NAT/NAT_HELPER
last seen2020-06-13
modified2017-07-24
published2006-12-08
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5614
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/dos/windows/nat/nat_helper.rb
titleMicrosoft Windows NAT Helper Denial of Service