Denial of Service in Microsoft's Distributed Transaction Coordinator for Windows 2000

A Denial of Service (DoS) condition exists within Microsoft’s distributed transaction coordinator (DTC) for Win2K.

Ken Pfeil

April 21, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 19, 2002, by PeterGründl.

VERSIONS AFFECTED

·        All Windows 2000 systems not containing the patchreferenced in Microsoft Security Bulletin MS02-018

 

DESCRIPTION

ADenial of Service (DoS) condition exists within Microsoft’s distributedtransaction coordinator (DTC) for Win2K. An attacker sending 20,200null characters to the DTC service listening on TCP port 3372 can causemsdtc.exe to spike CPU usage at 100 percent, resulting in MSDTCrefusing connections and depleting kernel resources.

 


VENDOR RESPONSE

 

Thevendor, Microsoft, has released a patchthat resolves this vulnerability.

 

CREDIT
Discovered by PeterGründl.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like