Windows NT SNMP agent has a serious memory leak

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: NT SNMPAgent Leak

Platforms: Windows NT: 4.0, Windows NT: 4.0 SP4
Description:

A memory leak exists in the Windows NT 4.0 SNMP agent when it is queried multiple times. The program erroneously uses a memory buffer that it then never frees, which, in theory, could be exploited by a remote attacker to deplete a machine's memory resources.

Remedy:

Obtain and install the sms-fix post-SP4 hotfix for Windows NT 4.0 from Microsoft.

References:

Microsoft Knowledge Base Article Q196270, SNMP Agent Leaks Memory When Queried, http://support.microsoft.com/support/kb/articles/q196/2/70.asp


X-Force Logo
Know Your Risks