peter bassill · operator
$ cve CVE-2000-1218 JSON

CVE-2000-1218

9.8
CRITICAL · CVSS 3.1 · EPSS 6.3% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.26% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-346
On CISA KEVno
Public exploitnone known
Published2000-04-14
Last modified2026-06-16

Affected (5)

VendorProduct
microsoftwindows 2000
microsoftwindows 98
microsoftwindows 98se
microsoftwindows nt
microsoftwindows xp

References

→ the Explorer  ·  watch your stack  ·  NVD