The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.
Score: 1.9
Priority: P3 - Important (Medium)
Score: 0.397
Percentile:
0.97157
CVSS v3.1 Score: 7.5
Severity: HIGH