CVE-2009-3103
기본정보
  • 공개일 : 2009-09-09
  • 변경일 : 2011-06-24
CVSS 평가
  • 위험도: 10.0
  • 액세스 벡터 : NETWORK
  • 액세스 복잡성 : 낮음
  • 인증 : 없음
  • 기밀성 영향 : 전체
  • 무결성 영향 : 전체
  • 가용성 영향 : 전체
  • 출처 : http://nvd.nist.gov
  • 공개일 : 2009-09-10
설명

Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.

참조
취약 소프트웨어
  • microsoft windows_server_2008
  • microsoft windows_vista x64
  • microsoft windows_server_2008 itanium
  • microsoft windows_server_2008 itanium
  • microsoft windows_server_2008 sp2
  • microsoft windows_server_2008 x64
  • microsoft windows_server_2008 sp2
  • microsoft windows_vista
  • microsoft windows_vista x64
  • microsoft windows_server_2008 x32
  • microsoft windows_vista
  • microsoft windows_vista