← Vulnerability feed

Vulnerability record · CVE-2000-1039 · published 9 January 2001

CVE-2000-1039: Windows TCP/IP stacks vulnerable to NAPTHA denial of service

Microsoft · Windows 95

CVE-2000-1039 covers the NAPTHA class of denial-of-service flaws in various TCP/IP stacks and network applications, including Microsoft Windows 95, 98, 98SE, ME and NT. A remote attacker floods a target with TCP connection attempts and completes the handshake without keeping connection state on the attacker host, exhausting the target's resources. The record is explicitly abstract and may change as the community learns more about affected applications.

5.0 CVSS 2.0 Medium EPSS 46% · top 1.2%
5.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityRemote unauthenticated availability impact with public exploit material, but limited to legacy Windows platforms and rated MEDIUM (CVSS 5.0).

What it is

CVE-2000-1039 covers the NAPTHA class of denial-of-service flaws in various TCP/IP stacks and network applications, including Microsoft Windows 95, 98, 98SE, ME and NT. A remote attacker floods a target with TCP connection attempts and completes the handshake without keeping connection state on the attacker host, exhausting the target's resources. The record is explicitly abstract and may change as the community learns more about affected applications.

Impact

An attacker can consume connection and memory resources on the target, degrading or denying network service to legitimate users. No confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. Any host running an affected TCP/IP stack or network application that accepts TCP connections is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.45833 (98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware use is documented.

What to do

  • Apply the vendor patches referenced in Microsoft bulletin MS00-091 and CERT advisory CA-2000-21 for affected Windows versions.
  • Retire or isolate unsupported Windows 95, 98, 98SE, ME and NT systems that cannot be patched.
  • Enable TCP SYN flood protection and connection rate limiting on perimeter devices and hosts.
  • Reduce half-open connection timeouts and cap concurrent connections where the stack allows it.
  • Monitor for sustained connection floods and rate-limit or block offending sources.

Detection

  • Alert on spikes in half-open or incomplete TCP connections to a single host.
  • Baseline normal connection rates per host and flag sustained deviations.
  • Watch for many completed handshakes from few sources that are not followed by application data.
  • Review firewall and IDS logs for repeated connection attempts against the same destination.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed7.8CVE-2002-0367Windows NT/2000 smss.exe debugging subsystem privilege escalationThe smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a lo…KEVEPSS 4.9%analysed10.0CVE-2005-1208Windows HTML Help integer overflow enables remote code executionA crafted compiled Help (.CHM) file with an oversized size field triggers an integer overflow and heap-based buffer overflow in Microsoft Windows HTM…EPSS 47%analysed10.0CVE-2005-0059Microsoft Windows Message Queuing buffer overflow allows remote code executionThe Message Queuing component in Microsoft Windows 2000 and Windows XP SP1 contains a buffer overflow that can be triggered by a crafted message. A r…EPSS 73%analysed10.0CVE-2005-0050Windows License Logging Service buffer overflow via unvalidated message lengthThe License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an …EPSS 47%analysed10.0CVE-2004-0571Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…EPSS 31%10.0CVE-2004-0901Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…EPSS 32%10.0CVE-2004-0568Microsoft windows 2000 vulnerabilityHyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that…EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2000-1039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.