PT-2018-1028 · Microsoft · Windows Server 2012 R2+4

Eric Schayes

+1

·

Publicado

2018-02-13

·

Atualizado

2025-08-05

·

CVE-2018-0833

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows 8.1 and RT 8.1 Windows Server 2012 R2
Description The issue is related to how specially crafted requests are handled by the Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client, leading to a denial of service vulnerability. This vulnerability is caused by insufficient input validation in the mrxsmb.sys module, which implements the SMBv2/SMBv3 protocol in Windows operating systems. An attacker could exploit this vulnerability by sending a specially crafted packet, allowing them to cause a denial of service in the SMB client.
Recommendations For Windows 8.1 and RT 8.1, apply the necessary patches or updates to fix the issue. For Windows Server 2012 R2, apply the necessary patches or updates to fix the issue. As a temporary workaround, consider restricting access to the SMB client to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00316
CVE-2018-0833
ZDI-18-166

Produtos afetados

Server Message Block
Windows
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2