Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
BID:26777
Info
Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
| Bugtraq ID: | 26777 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-5351 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Dec 19 2007 01:51PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Ultimate Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise Microsoft Windows Vista Business Microsoft Windows Vista 0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability because it fails to properly validate digital signatures.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of logged-in users. This facilitates the remote compromise of affected computers.
Microsoft Windows is prone to a remote code-execution vulnerability because it fails to properly validate digital signatures.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of logged-in users. This facilitates the remote compromise of affected computers.
Exploit / POC
Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Vista 0
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Vista x64 Edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB942624)
http://www.microsoft.com/downloads/details.aspx?FamilyId=05a9501c-4da3 -4fa1-901e-99cb262e5e36&displaylang=en
Microsoft Windows Vista 0
-
Microsoft Security Update for Windows Vista (KB942624)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9d22a9ee-cc08 -4b2d-af4e-55d326f82761&displaylang=en
References
Microsoft Windows SMBv2 Code Signing Remote Code Execution Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft)
- Microsoft Security Bulletin MS07-063 �?? Important (Microsoft)
- Vulnerability Note VU#520465 Microsoft SMBv2 signing vulnerability (US-CERT)