9.8

CVE-2000-1218

The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version -
Microsoft ≫ Windows 98 Version -
Microsoft ≫ Windows 98se Version -
Microsoft ≫ Windows Nt Version 4.0
Microsoft ≫ Windows Xp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.09% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

http://www.kb.cert.org/vuls/id/458659
Third Party Advisory
US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/4280
Third Party Advisory
VDB Entry