Vulnerability record · CVE-2000-1039 · published 9 January 2001
CVE-2000-1039: Windows TCP/IP stacks vulnerable to NAPTHA denial of service
Microsoft · Windows 95
CVE-2000-1039 covers the NAPTHA class of denial-of-service flaws in various TCP/IP stacks and network applications, including Microsoft Windows 95, 98, 98SE, ME and NT. A remote attacker floods a target with TCP connection attempts and completes the handshake without keeping connection state on the attacker host, exhausting the target's resources. The record is explicitly abstract and may change as the community learns more about affected applications.
Description
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated availability impact with public exploit material, but limited to legacy Windows platforms and rated MEDIUM (CVSS 5.0).
What it is
CVE-2000-1039 covers the NAPTHA class of denial-of-service flaws in various TCP/IP stacks and network applications, including Microsoft Windows 95, 98, 98SE, ME and NT. A remote attacker floods a target with TCP connection attempts and completes the handshake without keeping connection state on the attacker host, exhausting the target's resources. The record is explicitly abstract and may change as the community learns more about affected applications.
Impact
An attacker can consume connection and memory resources on the target, degrading or denying network service to legitimate users. No confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. Any host running an affected TCP/IP stack or network application that accepts TCP connections is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.45833 (98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware use is documented.
What to do
- Apply the vendor patches referenced in Microsoft bulletin MS00-091 and CERT advisory CA-2000-21 for affected Windows versions.
- Retire or isolate unsupported Windows 95, 98, 98SE, ME and NT systems that cannot be patched.
- Enable TCP SYN flood protection and connection rate limiting on perimeter devices and hosts.
- Reduce half-open connection timeouts and cap concurrent connections where the stack allows it.
- Monitor for sustained connection floods and rate-limit or block offending sources.
Detection
- Alert on spikes in half-open or incomplete TCP connections to a single host.
- Baseline normal connection rates per host and flag sustained deviations.
- Watch for many completed handshakes from few sources that are not followed by application data.
- Review firewall and IDS logs for repeated connection attempts against the same destination.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html | |
| http://razor.bindview.com/publish/advisories/adv_NAPTHA.html | |
| http://www.cert.org/advisories/CA-2000-21.html | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/2022 | ExploitPatchVendor Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-091 | |
| http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html | |
| http://razor.bindview.com/publish/advisories/adv_NAPTHA.html | |
| http://www.cert.org/advisories/CA-2000-21.html | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/2022 | ExploitPatchVendor Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-091 |
Track CVE-2000-1039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-1039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.