CVE-2007-0066 is a denial-of-service vulnerability affecting the kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 when ICMP Router Discovery Protocol (RDP) is enabled. Remote attackers can exploit this by sending fragmented router advertisement ICMP packets, leading to an out-of-bounds read. This vulnerability has a CVSS score of 7.1, indicating high severity, and allows for a complete denial of service (A:C) with medium attack complexity (AC:M) and no authentication required (Au:N). The EPSS score and FAUCET Risk Score suggest a notable potential for impact despite its age. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with a large percentage of older vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:home_server:*:*:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:small_business_server:2003:*:sp1:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:gold:itanium:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.