Zero-Day Advisory
Fortinet Discovers Windows SharedAccess Denail-of-service Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a Denial-of-Service (DoS) vulnerability on Microsoft Windows SharedAccess service.
Microsoft Windows SharedAccess is also known as Internet Connection Sharing (ICS). It provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
The DoS vulnerability can occur when a DHCP request contains the DHCP message type DHCP_MESSAGE_DECLINE while there is no valid DHCP_OPTION_REQUESTEDIPADDR embedded in the same DHCP request.
Solutions
Users should apply the solution provided by Microsoft.
Timeline
Fortinet reported the vulnerability to Microsoft on September 15, 2022
Microsoft confirmed the vulnerability on September 23, 2022
Microsoft released a patch for the vulnerability on December 13, 2022