Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-4037 | First vendor Publication | 2008-11-12 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4037 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-287 | Improper Authentication |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:6012 | |||
Oval ID: | oval:org.mitre.oval:def:6012 | ||
Title: | SMB Credential Reflection Vulnerability | ||
Description: | Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2008-4037 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Windows SMB credential reflection vulnerability | More info here |
ExploitDB Exploits
id | Description |
---|---|
2010-09-21 | Microsoft Windows SMB Relay Code Execution |
OpenVAS Exploits
Date | Description |
---|---|
2008-11-12 | Name : SMB Could Allow Remote Code Execution Vulnerability (957097) File : nvt/secpod_ms08-068_900057.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
49736 | Microsoft Windows SMB NTLM Authentication Credential Replay Remote Code Execu... Windows contains a flaw that may allow a malicious remote user to execute arbitrary code. The issue is triggered by a flaw that allows an attacker to replay the NTLM credentials of a client user. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | possible SMB replay attempt - overlapping encryption keys detected RuleID : 17723 - Revision : 12 - Type : OS-WINDOWS |
2014-01-10 | Telnet-based NTLM replay attack attempt RuleID : 15847 - Revision : 14 - Type : OS-WINDOWS |
2014-01-10 | SMB replay attempt via NTLMSSP - overlapping encryption keys detected RuleID : 15453 - Revision : 16 - Type : OS-WINDOWS |
2014-01-10 | Web-based NTLM replay attack attempt RuleID : 15124 - Revision : 17 - Type : OS-WINDOWS |
2014-01-10 | possible SMB replay attempt - overlapping encryption keys detected RuleID : 15009 - Revision : 22 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-11-12 | Name : It is possible to execute code on the remote host. File : smb_nt_ms08-068.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:13:01 |
|
2024-11-28 12:16:27 |
|
2024-08-02 12:09:45 |
|
2024-08-02 01:02:46 |
|
2024-02-02 01:09:19 |
|
2024-02-01 12:02:45 |
|
2023-12-07 21:28:06 |
|
2023-09-05 12:08:41 |
|
2023-09-05 01:02:36 |
|
2023-09-02 12:08:48 |
|
2023-09-02 01:02:37 |
|
2023-08-12 12:10:23 |
|
2023-08-12 01:02:37 |
|
2023-08-11 12:08:50 |
|
2023-08-11 01:02:43 |
|
2023-08-06 12:08:28 |
|
2023-08-06 01:02:39 |
|
2023-08-04 12:08:33 |
|
2023-08-04 01:02:41 |
|
2023-07-14 12:08:32 |
|
2023-07-14 01:02:39 |
|
2023-03-29 01:09:44 |
|
2023-03-28 12:02:45 |
|
2022-10-11 12:07:35 |
|
2022-10-11 01:02:28 |
|
2021-05-04 12:08:01 |
|
2021-04-22 01:08:22 |
|
2020-05-23 13:16:51 |
|
2020-05-23 00:22:14 |
|
2019-03-19 12:02:53 |
|
2018-10-31 00:19:53 |
|
2018-10-13 00:22:43 |
|
2017-09-29 09:23:42 |
|
2016-09-30 01:01:48 |
|
2016-06-28 17:17:49 |
|
2016-04-26 17:48:57 |
|
2014-02-17 10:46:32 |
|
2014-01-19 21:25:15 |
|
2013-05-11 00:25:37 |
|
2012-11-07 00:17:55 |
|