HomeinetDenial of service vulnerability returns to Windows

Denial of service vulnerability returns to Windows

Microsoft has warned of a new denial of service vulnerability that could disable computers running various versions of Windows, adding that there are no mitigations.

Denial of service windows vulnerability

The vulnerability affects all versions of Windows from 7 to 10, including 8.1 RT, server 2008, server 2012, server 2016, as well as all other versions that do not have the latest security updates installed.

The vulnerability, codenamed CVE-2018-5391, is related to packet fragmentation, a process that adjusts the size of packets to match the MTU (maximum transmission unit) of the recipient.

IP fragmentation attacks are a well-known form of DoS (Denial of service) attack, where the "victim" system receives many small IP packets, which must be reassembled into their original form.

This is a TCP fragmentation attack, also known as a Teardrop attack, which prevents the recipient from reassembling packets. This attack has been around since Windows 3.1, where it crashed the operating system.

“The attacker could send many 8-byte packets, but without sending the last packet.” Thus, the “victim” computer, waiting for this last packet to reassemble it, could never complete the process, and “hung”.

The reason the computer stopped responding was because the processor reached its maximum usage level, and only came back up when the reassembly process was completed or canceled.

Microsoft recommends that all necessary updates be made, and in case this is not possible, it suggests using these two commands.

Netsh int ipv4 set global reassemblylimit=0 Netsh int ipv6 set global reassemblylimit=0

 

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS