9.8
CVSSv3

CVE-2000-1218

Published: 14/04/2000 Updated: 08/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote malicious users to poison the DNS cache.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows nt 4.0

microsoft windows xp -

microsoft windows 2000 -

microsoft windows 98 -

microsoft windows 98se -