PT-2010-4099 · Microsoft · Windows Server 2008+3

CVE-2010-2551

·

Published

2010-08-11

·

Updated

2023-12-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Vista versions SP1 through SP2 Microsoft Windows Server 2008 versions Gold through R2 Microsoft Windows 7
Description A denial of service issue exists due to improper validation of an internal variable in SMB packets. This allows remote attackers to cause a system hang by sending crafted SMBv1 or SMBv2 packets. The vulnerability can be exploited without authentication by sending a specially crafted network message to a computer running the Server service.
Recommendations For Microsoft Windows Vista versions SP1 through SP2, update to a newer version that includes the fix for this issue. For Microsoft Windows Server 2008 versions Gold through R2, update to a newer version that includes the fix for this issue. For Microsoft Windows 7, update to a newer version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SMB service to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2551

Affected Products

Windows
Windows 7
Windows Server 2008
Windows Vista