Short Name |
MISC:LLMNR-REVERSE-LOOKUP |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
MISC |
Keywords |
Reverse Lookup |
Release Date |
2011/04/11 |
Update Number |
1900 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against reverse name-to-IP functionality in DNSAPI.DLL. A successful attack can lead to arbitrary code execution.
Microsoft Windows is prone to a remote code-execution vulnerability. Successful exploits can allow attackers to execute arbitrary code within the context of the NetworkService account. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.