← Vulnerability feed

Vulnerability record · CVE-2013-3182 · published 14 August 2013

CVE-2013-3182: Windows NAT Driver ICMP Memory Corruption Denial of Service

Microsoft · Windows Server 2012

The Windows NAT Driver (winnat) service in Windows Server 2012 fails to properly validate memory addresses while processing ICMP packets, leading to memory corruption and a system hang. Because the service is reachable over the network without authentication, a remote attacker can crash or hang the affected server.

7.8 CVSS 2.0 High EPSS 95% · top 0.1% CWE-119 · Memory buffer overflow
7.8CVSS 2.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The Windows NAT Driver (aka winnat) service in Microsoft Windows Server 2012 does not properly validate memory addresses during the processing of ICMP packets, which allows remote attackers to cause a denial of service (memory corruption and system hang) via crafted packets, aka "Windows NAT Denial of Service Vulnerability."

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote denial of service with complete availability impact and very high EPSS, though no KEV listing or documented exploitation.

What it is

The Windows NAT Driver (winnat) service in Windows Server 2012 fails to properly validate memory addresses while processing ICMP packets, leading to memory corruption and a system hang. Because the service is reachable over the network without authentication, a remote attacker can crash or hang the affected server.

Impact

An unauthenticated remote attacker can cause memory corruption and a full system hang, denying service to all users and services on the host. There is no evidence in the record of code execution or data disclosure.

Attack surface

Reachable over the network via crafted ICMP packets sent to a Windows Server 2012 system running the NAT role; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record, but EPSS is very high (0.94683, 99.85th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply Microsoft security bulletin MS13-064 (the vendor fix for this issue) as the first action.
  • If the NAT role is not required, disable or remove the Windows NAT Driver (winnat) service on Windows Server 2012 hosts.
  • Restrict inbound ICMP to the server at the network perimeter and host firewall where operationally feasible.
  • Monitor Microsoft advisories for any updated guidance, since the NVD record is marked Modified.

Detection

  • Monitor Windows event logs and system reliability data for unexpected hangs or bugchecks on Windows Server 2012 hosts running the NAT role.
  • Alert on abnormal volumes or malformed patterns of inbound ICMP traffic directed at NAT-enabled servers.
  • Correlate host unavailability or reboot events with concurrent ICMP traffic spikes to identify denial-of-service attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2013-3182), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.