← back
CVE-2009-3563

CVE-2009-3563

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 32%
from disclosure to weapon0 days
Published on NVDDec 9
metasploitOct 4
exploitation probability
32%top 2% of all CVEs
observed exploitation
nono source reports it
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
Affected products
n/a · n/a