PT-2018-1028 · Microsoft · Windows Server 2012 R2+4
Eric Schayes
+1
·
Published
2018-02-13
·
Updated
2025-08-05
·
CVE-2018-0833
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Windows 8.1 and RT 8.1
Windows Server 2012 R2
Description
The issue is related to how specially crafted requests are handled by the Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client, leading to a denial of service vulnerability. This vulnerability is caused by insufficient input validation in the mrxsmb.sys module, which implements the SMBv2/SMBv3 protocol in Windows operating systems. An attacker could exploit this vulnerability by sending a specially crafted packet, allowing them to cause a denial of service in the SMB client.
Recommendations
For Windows 8.1 and RT 8.1, apply the necessary patches or updates to fix the issue.
For Windows Server 2012 R2, apply the necessary patches or updates to fix the issue.
As a temporary workaround, consider restricting access to the SMB client to minimize the risk of exploitation.
Exploit
Fix
DoS
RCE
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Server Message Block
Windows
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2