CVE-2017-0171HighCVSS 5.3

Windows DNS Server Denial of Service Vulnerability

Published
May 9, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A denial of service vulnerability exists in Windows DNS Server if the server is configured to answer version queries. An attacker who successfully exploited this vulnerability could cause the DNS Server service to become nonresponsive. An attacker could exploit this vulnerability by sending malicious DNS queries, resulting in denial of service. The update addresses the vulnerability by correcting how Windows DNS Server processes DNS queries.

🎯 Affected products12

  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)

✅ Remediation

KB4018196 (Security Update) KB4019264 (Monthly Rollup) KB4019263 (Security Only) KB4019216 (Monthly Rollup) KB4019214 (Security Only) KB4019215 (Monthly Rollup) KB4019213 (Security Only) KB4019472 (Security Update)

🔗 References (9)