CVE-2008-4037
Summary
| CVE | CVE-2008-4037 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-12 23:30:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | server_2003 | sp1 | All | All |
| Operating System | Microsoft | Windows | server_2003 | sp1 | itanium | All |
| Operating System | Microsoft | Windows | server_2003 | sp2 | All | All |
| Operating System | Microsoft | Windows | server_2003 | sp2 | itanium | All |
| Operating System | Microsoft | Windows | server_2003 | sp2 | x64 | All |
| Operating System | Microsoft | Windows | server_2003 | unknown | x64 | All |
| Operating System | Microsoft | Windows | xp | sp2 | All | All |
| Operating System | Microsoft | Windows | xp | sp2 | x64 | All |
| Operating System | Microsoft | Windows | xp | sp3 | All | All |
| Operating System | Microsoft | Windows | xp | unknown | x64 | All |
| Operating System | Microsoft | Windows 2000 | - | sp4 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | - | All | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | - | All | x64 | All |
| Operating System | Microsoft | Windows Vista | - | All | All | All |
| Operating System | Microsoft | Windows Vista | - | All | x64 | All |
| Operating System | Microsoft | Windows Vista | - | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Technical Cyber Security Alert TA08-316A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Page not found | af854a3a-2127-422b-91ae-364da2661108 | www.networkworld.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.securityfocus.com/data/vulnerabilities/exploits/backrush.patch.README | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| SmbRelay3 NTLM Replay Attack Tool/Exploit (MS08-068) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Microsoft Windows SMB Authentication Credential Replay Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Microsoft Windows SMB Credential Reflection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Windows Server Message Block NTLM Authentication Replay Bug Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Microsoft Fixes 8-year Old Design Flaw in SMB | af854a3a-2127-422b-91ae-364da2661108 | www.veracode.com | |
| www.securityfocus.com/data/vulnerabilities/exploits/backrush.patch | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| osvdb.org/49736 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| The SMB Man-In-the-Middle Attack | af854a3a-2127-422b-91ae-364da2661108 | www.xfocus.net | |
| Microsoft Security Bulletin MS08-068 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.