CVE-2016-9312 describes a denial-of-service vulnerability in ntpd versions prior to 4.2.8p9 when running on Microsoft Windows, allowing remote attackers to disrupt service by sending a large UDP packet. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity and a high impact on availability, requiring no user interaction or privileges. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community and media attention, with one article from SecurityWeek covering the patched DoS flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:p8:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.