Vulnerability CVE-2010-0017


Published: 2010-02-10   Modified: 2012-02-13

Description:
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."

See advisories in our WLB2 database:
Topic
Author
Date
High
Microsoft SMB Client Pool Overflow (MS10-006)
Laurent Gaffi, R...
16.02.2010

Type:

CWE-362

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Microsoft -> Windows 7 
Microsoft -> Windows server 2008 
Microsoft -> Windows vista 

 References:
http://www.us-cert.gov/cas/techalerts/TA10-040A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8298

Copyright 2024, cxsecurity.com

 

Back to Top