Vulnerability record · CVE-2013-3182 · published 14 August 2013
CVE-2013-3182: Windows NAT Driver ICMP Memory Corruption Denial of Service
Microsoft · Windows Server 2012
The Windows NAT Driver (winnat) service in Windows Server 2012 fails to properly validate memory addresses while processing ICMP packets, leading to memory corruption and a system hang. Because the service is reachable over the network without authentication, a remote attacker can crash or hang the affected server.
Description
The Windows NAT Driver (aka winnat) service in Microsoft Windows Server 2012 does not properly validate memory addresses during the processing of ICMP packets, which allows remote attackers to cause a denial of service (memory corruption and system hang) via crafted packets, aka "Windows NAT Denial of Service Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityUnauthenticated remote denial of service with complete availability impact and very high EPSS, though no KEV listing or documented exploitation.
What it is
The Windows NAT Driver (winnat) service in Windows Server 2012 fails to properly validate memory addresses while processing ICMP packets, leading to memory corruption and a system hang. Because the service is reachable over the network without authentication, a remote attacker can crash or hang the affected server.
Impact
An unauthenticated remote attacker can cause memory corruption and a full system hang, denying service to all users and services on the host. There is no evidence in the record of code execution or data disclosure.
Attack surface
Reachable over the network via crafted ICMP packets sent to a Windows Server 2012 system running the NAT role; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record, but EPSS is very high (0.94683, 99.85th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply Microsoft security bulletin MS13-064 (the vendor fix for this issue) as the first action.
- If the NAT role is not required, disable or remove the Windows NAT Driver (winnat) service on Windows Server 2012 hosts.
- Restrict inbound ICMP to the server at the network perimeter and host firewall where operationally feasible.
- Monitor Microsoft advisories for any updated guidance, since the NVD record is marked Modified.
Detection
- Monitor Windows event logs and system reliability data for unexpected hangs or bugchecks on Windows Server 2012 hosts running the NAT role.
- Alert on abnormal volumes or malformed patterns of inbound ICMP traffic directed at NAT-enabled servers.
- Correlate host unavailability or reboot events with concurrent ICMP traffic spikes to identify denial-of-service attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-3182 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3182), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.