TCP/IP Stack Denial of Service Vulnerability in Multiple Operating Systems
CVE-2005-1184

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
2 May 2005

Summary

A vulnerability exists in the TCP/IP stack of several operating systems that could be exploited by remote attackers. By sending specially crafted TCP packets with a valid sequence number but an incorrect acknowledgment number, attackers can trigger excessive CPU usage due to the generation of numerous 'keep alive' packets. This can lead to a denial of service, impacting system performance and availability. Although reports indicate that replication of such conditions might be challenging, the potential for disruption remains significant.

References

EPSS Score

44% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.