Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
BID:36989
Info
Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
| Bugtraq ID: | 36989 |
| Class: | Design Error |
| CVE: |
CVE-2009-3676 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2009 12:00AM |
| Updated: | May 07 2010 11:02AM |
| Credit: | Laurent Gaffie |
| Vulnerable: |
Nortel Networks Symposium Agent Nortel Networks ENSM IP Address Manager 0 Nortel Networks ENSM - Enterprise NMS 10.5 Nortel Networks ENSM - Enterprise NMS 10.4 Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Manager Server 7.1 Nortel Networks Contact Center Manager Server 7.0 Nortel Networks Contact Center Manager Server 6.0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express 7.1 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.1 Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center - TAPI Server 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 R2 Microsoft Windows 7 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Enterprise Edition Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
Microsoft Windows is prone to a remote denial-of-service vulnerability.
A remote attacker can exploit this issue to crash the Windows kernel, denying service to legitimate users.
The issue affects Windows 7 and 2008 R2.
Microsoft Windows is prone to a remote denial-of-service vulnerability.
A remote attacker can exploit this issue to crash the Windows kernel, denying service to legitimate users.
The issue affects Windows 7 and 2008 R2.
Exploit / POC
Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems R2
Microsoft Windows Server 2008 for Itanium-based Systems R2
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB980232)
http://www.microsoft.com/downloads/details.aspx?familyid=CD1A046E-915D -4904-B753-5A24BE10C504
Microsoft Windows Server 2008 for Itanium-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB980232)
http://www.microsoft.com/downloads/details.aspx?familyid=541E9E2F-EC1D -42B2-AAE5-481C0D435169
References
Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
References:
References:
- Avaya Enterprise (Fomerly Nortel Enterprise) Response to Microsoft Security (Avaya)
- Microsoft Homepage (Microsoft)
- Microsoft Security Advisory 977544 Released (Microsoft Security Response Center)
- Microsoft Windows 7 Homepage (Microsoft)
- MS10-020 Vulnerabilities in SMB Client Could Allow Remote Code Execution (980232 (Avaya)
- SA37347 / CVE-2009-3676 (Secunia)
- Windows Server 2008 Product Page (Microsoft)
- Microsoft Security Advisory (977544) (Microsoft)
- Microsoft Security Bulletin MS10-020 (Microsoft)