Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0017 | First vendor Publication | 2010-02-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0017 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:8298 | |||
Oval ID: | oval:org.mitre.oval:def:8298 | ||
Title: | SMB Client Race Condition Vulnerability | ||
Description: | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-0017 | Version: | 6 |
Platform(s): | Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2010-02-10 | Name : Microsoft SMB Client Remote Code Execution Vulnerabilities (978251) File : nvt/secpod_ms10-006.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
62243 | Microsoft Windows SMB Client Packet Handling Race Condition Remote Privilege ... Windows contains a flaw that may allow a remote attacker to execute arbitrary code or allow a local attacker to elevate privileges. The issue is triggered by a specially crafted SMB response to client-initiated SMB request or specially crafted SMB negotiate responses. |
Snort® IPS/IDS
Date | Description |
---|---|
2018-06-12 | SMB client NULL deref race condition attempt RuleID : 46637 - Revision : 1 - Type : NETBIOS |
2014-01-10 | SMB client NULL deref race condition attempt RuleID : 16418 - Revision : 10 - Type : NETBIOS |
2014-01-10 | Microsoft Windows SMB Negotiate Protocol Response overflow attempt RuleID : 16417 - Revision : 12 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-09 | Name : Arbitrary code can be executed on the remote host through its SMB client. File : smb_nt_ms10-006.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:25 |
|
2024-11-28 12:20:49 |
|
2023-12-07 21:28:04 |
|
2021-05-04 12:10:54 |
|
2021-04-22 01:11:26 |
|
2020-05-23 13:16:54 |
|
2020-05-23 00:25:01 |
|
2018-10-31 00:20:00 |
|
2018-10-13 00:22:53 |
|
2017-09-19 09:23:34 |
|
2016-08-31 12:02:01 |
|
2016-08-05 12:02:22 |
|
2016-06-28 17:59:20 |
|
2016-04-26 19:29:11 |
|
2016-03-05 09:21:15 |
|
2016-03-05 05:20:44 |
|
2014-02-17 10:53:02 |
|
2014-01-19 21:26:27 |
|
2013-05-10 23:13:00 |
|