Koozali.org: home of the SME Server

Win2k/XP PPTP vulnerability

Bill Talcott

Win2k/XP PPTP vulnerability
« on: October 31, 2002, 05:21:47 PM »
Since a lot of people here are using PPTP VPNs, I thought I'd pass this on.

http://www.microsoft.com/technet/security/bulletin/MS02-063.asp

It's an unchecked buffer denial of service exploit. To attack a client, they'd need to do it during an active PPTP session, and it is very difficult to make it do anything other than crash (i.e. run code). Probably not a big concern, but you should patch it up...