Vulnerability record · CVE-2004-0790 · published 12 April 2005
CVE-2004-0790: TCP/IP and ICMP implementations allow blind connection-reset DoS
Microsoft · Windows 2000
Multiple TCP/IP and ICMP implementations accept spoofed ICMP error messages that can tear down established TCP connections, a flaw known as the blind connection-reset attack. Because the attacker never needs to see the traffic, any off-path host can disrupt long-lived sessions. The record covers several Windows and Solaris versions but does not enumerate exact affected builds.
Description
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is remotely triggerable with no authentication and has very high EPSS, but it only causes availability loss and affects legacy platforms with patches available since 2005-2006.
What it is
Multiple TCP/IP and ICMP implementations accept spoofed ICMP error messages that can tear down established TCP connections, a flaw known as the blind connection-reset attack. Because the attacker never needs to see the traffic, any off-path host can disrupt long-lived sessions. The record covers several Windows and Solaris versions but does not enumerate exact affected builds.
Impact
An attacker can reset arbitrary TCP connections between two victims, causing denial of service for sessions such as BGP, VPN or other long-lived connections. No data is read or modified; the effect is availability loss.
Attack surface
Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker only needs to send crafted ICMP error messages with spoofed source addresses toward a target.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high at 0.80 (99.6th percentile), indicating strong predicted exploitation activity. No public exploit code is confirmed by the supplied references.
What to do
- Apply vendor patches, starting with Microsoft MS05-019/MS06-064 and the Sun Solaris advisories referenced in the record.
- Filter or rate-limit inbound ICMP error messages at network boundaries where operationally feasible.
- Enable TCP hardening options that validate ICMP error payloads against existing connection state, where the stack supports it.
- Reduce reliance on long-lived unauthenticated TCP sessions for critical control-plane traffic, or protect them with cryptographic session integrity.
- Retire or isolate unsupported Windows 98/ME and legacy Solaris systems that cannot be patched.
Detection
- Monitor for bursts of TCP RSTs or connection teardowns on long-lived sessions without corresponding application errors.
- Alert on inbound ICMP unreachable, source-quench or parameter-problem messages that do not correlate with legitimate network events.
- Baseline ICMP error volume per source and flag spoofed or unexpected sources sending ICMP errors to TCP endpoints.
- Correlate sudden BGP, VPN or other session resets across multiple peers within a short window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0790 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0790), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.