PT-2009-1115 · Microsoft · Smbv2+4
Published
2009-10-14
·
Updated
2023-12-07
·
CVE-2009-2526
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista versions Gold, SP1, and SP2
Microsoft Windows Server 2008 versions Gold and SP2
Description
The issue is related to the SMBv2 component in the Windows operating system, which is associated with resource management errors. This allows a remote attacker to cause a denial of service, resulting in an infinite loop and system hang, by sending a crafted packet to the Server service. The vulnerability can be exploited without authentication, enabling an attacker to send a specially crafted network message to a computer running the Server service, causing the computer to stop responding until restarted.
Recommendations
For Microsoft Windows Vista versions Gold, SP1, and SP2, update the system to prevent the exploitation of this issue.
For Microsoft Windows Server 2008 versions Gold and SP2, update the Server service to prevent the exploitation of this issue.
As a temporary workaround, consider restricting access to the Server service to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008
Windows Vista
Smbv2
Server Service
Windows