Vulnerability record · CVE-2013-0075 · published 13 February 2013
CVE-2013-0075: Windows TCP/IP crafted FIN packet causes reboot denial of service
Microsoft · Windows Vista
The TCP/IP stack in multiple Microsoft Windows versions mishandles a crafted packet that terminates a TCP connection, allowing a remote attacker to force a reboot. Because the flaw is in the core network stack and needs no credentials, any reachable Windows host is a potential target, making it a serious availability risk.
Description
The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityRemote, unauthenticated, low-complexity denial of service against core Windows networking with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.
What it is
The TCP/IP stack in multiple Microsoft Windows versions mishandles a crafted packet that terminates a TCP connection, allowing a remote attacker to force a reboot. Because the flaw is in the core network stack and needs no credentials, any reachable Windows host is a potential target, making it a serious availability risk.
Impact
An attacker gains the ability to remotely reboot an affected Windows system, causing a denial of service. Repeated packets can keep a host offline, disrupting services and business operations.
Attack surface
Reachable over the network via a crafted TCP packet that terminates a connection; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing TCP to an attacker is in scope.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.70 (99th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Apply Microsoft security bulletin MS13-018 for the affected Windows versions as the primary fix.
- Where patching is delayed, restrict inbound TCP exposure to trusted networks and block unnecessary ports at the perimeter.
- Segment or isolate legacy systems that cannot be patched to limit reachability from untrusted networks.
- Monitor vendor and US-CERT advisories for updated guidance on this issue.
Detection
- Alert on unexpected system reboots or unexpected shutdown events on Windows hosts, especially clustered or repeated occurrences.
- Monitor network traffic for anomalous TCP FIN or connection-termination patterns targeting affected hosts.
- Correlate reboot events with inbound TCP traffic from untrusted sources to identify likely trigger packets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0075), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.