Description
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.
Product(s):
- Microsoft Windows 2000
- Microsoft Windows 2000 Service Pack 1
- Microsoft Windows 2000 Service Pack 2
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows 2000 Japanese Server Edition
- Microsoft Windows 2000 Advanced Server Edition
- Microsoft Windows 2000 Datacenter Server Edition
- Microsoft Windows 2000 Professional Edition
- Microsoft Windows 2000 Server Edition
- Microsoft Windows 2000 Beta 3
- Microsoft windows 2000_gold
- Microsoft Windows 2000 Addvanced Server (Initial Release)
- Microsoft Windows 2000 Datacenter Server (Initial Release)
- Microsoft Windows 2000 Professional (Initial release)
- Microsoft Windows 2000 Server (Inital release)
- Microsoft windows 2000_rc1
- Microsoft windows 2000_rc2
- Microsoft windows 2000_sp1
- Microsoft Windows 2000 Service Pack 1 Advanced Server Edition
- Microsoft Windows 2000 Service Pack 1 Datacenter Server Edition
- Microsoft Windows 2000 Service Pack 1 Professional Edition
- Microsoft Windows 2000 Service Pack 1 Server Edition
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Server SP1
- Microsoft windows 2000_sp2
- Microsoft Windows 2000 Service Pack 2 Advanced Server Edition
- Microsoft Windows 2000 Service Pack 2 Datacenter Server Edition
- Microsoft Windows 2000 Service Pack 2 Professional Edition
- Microsoft Windows 2000 Service Pack 2 Server Edition
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Server SP2
- Microsoft windows 2000_sp3
- Microsoft Windows 2000 Service Pack 3 Advanced Server Edition
- Microsoft Windows 2000 Service Pack 3 Datacenter Server Edition
- Microsoft Windows 2000 Service Pack 3 Professional Edition
- Microsoft Windows 2000 Service Pack 3 Server Edition
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Datacenter Server SP3
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Service Pack 4 Advanced Server Edition
- Microsoft Windows 2000 Service Pack 4 Datacenter Server Edition
- Microsoft Windows 2000 Service Pack 4 Professional Edition
- Microsoft Windows 2000 Service Pack 4 Server Edition
- Microsoft Windows 2000 Service Pack 4 French
- Microsoft Windows 2000 Advanced Server SP4
- Microsoft Windows 2000 Datacenter Server SP4
- Microsoft Windows 2000 Professional SP4
- Microsoft Windows 2000 Server SP4
- Microsoft windows 2000_beta3
- Microsoft Windows 2003 Server Enterprise Edition 64-bit
- Microsoft Windows 2003 Server Enterprise 64-bit
- Microsoft Windows 2003 Server R2 64-bit
- Microsoft Windows 2003 Server R2 Datacenter 64-bit
- Microsoft Windows 2003 Server Standard on 64-bit
- Microsoft Windows 2003 Server Web Edition
- Microsoft Windows NT 4.0 Enterprise Server
- Microsoft Windows NT 4.0 Server
- Microsoft Windows NT 4.0 Terminal Server
- Microsoft Windows NT 4.0 Workstation
- Microsoft Windows 4.0 gold server
- Microsoft Windows NT 4.0 Terminal Server Edition (Initial release)
- Microsoft Windows 4.0 gold workstation
- Microsoft Windows NT 4.0 Service Pack 1 Enterprise Server
- Microsoft Windows 4.0 sp1 server
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows 4.0 sp1 workstation
- Microsoft Windows NT 4.0 Service Pack 2 Enterprise Server
- Microsoft Windows 4.0 sp2 server
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows 4.0 sp2 workstation
- Microsoft Windows NT 4.0 Service Pack 3 Enterprise Server
- Microsoft Windows 4.0 sp3 server
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows 4.0 sp3 workstation
- Microsoft Windows NT 4.0 Service Pack 4 Enterprise Server
- Microsoft Windows 4.0 sp4 server
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows 4.0 sp4 workstation
- Microsoft Windows NT 4.0 Service Pack 5 Enterprise Server
- Microsoft Windows 4.0 sp5 server
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows 4.0 sp5 workstation
- Microsoft Windows NT 4.0 Service Pack 6 Enterprise Server
- Microsoft Windows 4.0 sp6 server
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows 4.0 sp6 workstation
- Microsoft Windows NT 4.0 Service Pack 6a Enterprise Server
- Microsoft Windows 4.0 sp6a server
- Microsoft Windows NT Terminal Server 4.0 SP6a
- Microsoft Windows 4.0 sp6a workstation
- Microsoft Windows NT 4.0 Server Post Service Pack 6a Security Rollup
- Microsoft Windows NT 4.0 Service Roll-up Terminal Server
- +9 additional
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2003-0661, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2003-0661 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.