Vulnerability Note VU#652537
Microsoft Windows SMB packet validation vulnerability
A vulnerability in the way that Microsoft Windows handles some SMB packets could allow remote attackers to execute code of their choosing on a vulnerable system.
The Microsoft Server Message Block (SMB), and its follow-on, Common Internet File System (CIFS), are network protocols that Windows uses to share files, printers, serial ports, and communicate between computers. A vulnerability exists in the way that the affected operating systems validate certain incoming SMB packets. Additional details about the underlying cause of the vulnerability are not known.
An unauthenticated remote attacker may be able to exploit this vulnerability by sending specially-crafted SMB packets to a vulnerable system. Microsoft reports that this vulnerability may also be exploited through a malicious web page. In this scenario, an attacker would need to trick or persuade a user into browsing the malicious web page or following a link to the malicious web page provided in an email message.
A remote, unauthenticated attacker could execute arbitrary code on a vulnerable system.
Apply a patch
Systems Affected (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Microsoft Corporation||Affected||-||08 Feb 2005|
CVSS Metrics (Learn More)
Thanks to Microsoft Security for reporting this vulnerability. Microsoft, in turn, credits eEye Digital Security with reporting this vulnerability to them.
This document was written by Chad R Dougherty, based upon information provided by Microsoft.
- CVE IDs: CAN-2005-0045
- Date Public: 08 Feb 2005
- Date First Published: 08 Feb 2005
- Date Last Updated: 11 May 2005
- Severity Metric: 27.09
- Document Revision: 7
If you have feedback, comments, or additional information about this vulnerability, please send us email.