NTP: Network Time Protocol Windows Daemon getEndptFromIoCtx Denial of Service

A denial of service vulnerability has been reported in the Windows port of Network Time Foundation's NTP Daemon. Successful exploitation results in denial of service conditions on the target server.

Extended Description

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

References

CVE: CVE-2016-9312

Short Name
NTP:WIN-PORT-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
NTP
Keywords
CVE-2016-9312 Daemon Denial Network Protocol Service Time Windows getEndptFromIoCtx of
Release Date
12/22/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
CVSS Score

5.0

Found a potential security threat?