Vulnerability record · CVE-2007-0069 · published 8 January 2008
CVE-2007-0069: Microsoft Windows kernel memory corruption via IGMPv3 and MLDv2 packets
Microsoft · Windows 2003 Server
The Windows kernel mishandles crafted IGMPv3 and MLDv2 network packets, causing memory corruption. This can lead to denial of service through CPU consumption and possibly remote code execution. The flaw affects Windows XP SP2, Server 2003, and Vista.
Description
Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS score of 9.3 with remote, unauthenticated code execution potential and high EPSS probability.
What it is
The Windows kernel mishandles crafted IGMPv3 and MLDv2 network packets, causing memory corruption. This can lead to denial of service through CPU consumption and possibly remote code execution. The flaw affects Windows XP SP2, Server 2003, and Vista.
Impact
An attacker can cause a denial of service by exhausting CPU resources, and may be able to execute arbitrary code in kernel context, potentially taking full control of the system.
Attack surface
The vulnerability is reachable remotely over the network by sending specially crafted IGMPv3 or MLDv2 packets; no authentication is required, but the CVSS vector indicates medium attack complexity.
Exploitation
The vulnerability is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.492, 98.8th percentile). References include patch and vendor advisory tags, but no public exploit tags are present.
What to do
- Apply the Microsoft security update MS08-001 immediately.
- Disable IGMPv3 and MLDv2 processing on affected systems if the patch cannot be applied.
- Block IGMP and MLD traffic at network boundaries where feasible.
- Upgrade to a supported Windows version if still running XP, Server 2003, or Vista.
Detection
- Monitor for unusual IGMPv3 or MLDv2 packet patterns or malformed packets on the network.
- Check system logs for unexpected kernel crashes or high CPU usage spikes.
- Use network intrusion detection signatures for CVE-2007-0069 if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.