PT-2018-1650 · Microsoft · Windows Server 2012 R2+6
Haikuo Xie
·
Published
2018-09-11
·
Updated
2018-11-20
·
CVE-2018-8444
CVSS v2.0
6.6
Medium
| Vector | AV:N/AC:H/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Server Message Block 2.0 (SMBv2) versions prior to the fixed version, affecting Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2.
Description
The issue is related to how the SMBv2 server handles certain requests, leading to an information disclosure vulnerability. This can allow a remote attacker to disclose protected information using specially crafted SMBv2 requests.
Recommendations
For Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, update to a version that includes the fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smbv2
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2012 R2