The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 2000
OSMicrosoftall versionsMicrosoft Windows 98
OSMicrosoftall versionsMicrosoft Windows 98se
OSMicrosoftall versionsMicrosoft Windows Nt
OSMicrosoft4.0Microsoft Windows Xp
OSMicrosoftall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE
CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
CVE-2019-5620CRITICAL9.8PL ✓same product
Brak uwierzytelnienia dla krytycznej funkcji w ABB MicroSCADA Pro SYS600
CVE-2020-7485CRITICAL9.8PL ✓same product
Ukryte konto serwisowe w Schneider Electric TriStation umożliwia nieautoryzowany dostęp
CVE-2012-1891CRITICAL9.8PL ✓same product
RCE w Microsoft MDAC/WDAC — heap buffer overflow przez dane XML