CVE-2006-0988
Last modified
CVE-2006-0988 is a vulnerability of currently unknown severity. The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.. EPSS estimates a 54.79% chance of exploitation in the next 30 days.
Description
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2003 Server | r2 |
| Microsoft | Windows Nt | 4.0 |
References
- http://www.us-cert.gov/reading_room/DNS-recursion121605.pdfPatch, Vendor Advisory
- http://www.us-cert.gov/reading_room/DNS-recursion121605.pdfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0988?
How severe is CVE-2006-0988?
How do I fix CVE-2006-0988?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0982The on-access scanner for McAfee Virex 7.7 for Macintosh, in…
- CVE-2006-0983Cross-site scripting (XSS) vulnerability in index.php in Qwi…
- CVE-2006-0984Cross-site scripting (XSS) vulnerability in inc_header.php i…
- CVE-2006-0985Multiple cross-site scripting (XSS) vulnerabilities in the "…
- CVE-2006-0986WordPress 2.0.1 and earlier allows remote attackers to obtai…
- CVE-2006-0987The default configuration of ISC BIND before 9.4.1-P1, when …
- CVE-2006-0989Stack-based buffer overflow in the volume manager daemon (vm…
- CVE-2006-0990Stack-based buffer overflow in the NetBackup Catalog daemon …
- CVE-2006-0991Buffer overflow in the NetBackup Sharepoint Services server …
- CVE-2006-0992Stack-based buffer overflow in Novell GroupWise Messenger be…
- CVE-2006-0993The web management interface in 3Com TippingPoint SMS Server…
- CVE-2006-0994Multiple Sophos Anti-Virus products, including Anti-Virus fo…
Are you affected by CVE-2006-0988?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
