Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/dailydave/2011/q2/25 - | |
References | () http://seclists.org/fulldisclosure/2011/Apr/254 - |
Information
Published : 2012-02-02 17:55
Updated : 2024-11-21 01:21
NVD link : CVE-2010-4562
Mitre link : CVE-2010-4562
CVE.ORG link : CVE-2010-4562
JSON object : View
Products Affected
microsoft
- windows_server_2008
- windows_vista
- windows_2003_server
- windows_xp
- windows_7
- windows_2000
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor