CVE-2007-0066

high Microsoft
CVSS v3 Base Score
7.1
AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Score
27.2%
Exploitation probability in 30 days
Top 4% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
None
Availability
C
Published: January 8, 2008 (6700 days ago)
Last Modified: April 23, 2026
Vendor: Microsoft
Source: NVD

Description

The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."

CWE

NVD-CWE-Other

Affected Products

microsoft home servermicrosoft small business servermicrosoft windows 2000microsoft windows 2003 servermicrosoft windows server 2003microsoft windows xp

References