PT-2009-5948 · Microsoft · Windows 7+2
Laurent Gaffié
·
Published
2009-11-13
·
Updated
2018-10-30
·
CVE-2009-3676
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Description
A denial of service issue exists in the Microsoft Server Message Block (SMB) client implementation, allowing remote SMB servers and man-in-the-middle attackers to cause a system hang via a specially crafted SMB response packet. This can be achieved by sending an SMBv1 or SMBv2 response packet with an incorrect length value in a NetBIOS header or an additional length field at the end of the response packet. An attempt to exploit this issue does not require authentication, and a successful exploitation could cause the computer to stop responding until restarted.
Recommendations
For Microsoft Windows Server 2008 R2, apply the necessary patch to fix the SMB client implementation.
For Microsoft Windows 7, apply the necessary patch to fix the SMB client implementation.
As a temporary workaround, consider restricting access to SMB services until a patch is available.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows 7
Windows Server 2008 R2
Windows