Microsoft Corporation Information for VU#637934

TCP does not adequately validate segments before updating timestamp value



Vendor Statement

Changes made during the development of Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and the MS05-019 security update eliminated this vulnerability. If you have installed any of these updates, you are protected from this vulnerability and no further action is required. See

for more information about this issue.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



Please refer to and

If you have feedback, comments, or additional information about this vulnerability, please send us email.