Announcement

Collapse
No announcement yet.

Zero Day Exploit Allows Attackers To Cause A System Crash

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Zero Day Exploit Allows Attackers To Cause A System Crash

    Vulnerability Note VU#867968

    Microsoft Windows SMB Tree Connect Response denial of service vulnerability

    Original Release date: 02 Feb 2017 | Last revised: 03 Feb 2017

    Overview

    Microsoft Windows contains a memory corruption bug in the handling of SMB traffic, which may allow a remote, unauthenticated attacker to cause a denial of service on a vulnerable system.

    Description

    Microsoft Windows fails to properly handle traffic from a malicious server. In particular, Windows fails to properly handle a specially-crafted server response that contains too many bytes following the structure defined in the SMB2 TREE_CONNECT Response structure.

    By connecting to a malicious SMB server, a vulnerable Windows client system may crash (BSOD) in mrxsmb20.sys. We have confirmed the crash with fully-patched Windows 10 and Windows 8.1 client systems, as well as the server equivalents of these platforms, Windows Server 2016 and Windows Server 2012 R2.

    Note that there are a number of techniques that can be used to trigger a Windows system to connect to an SMB share. Some may require little to no user interaction.

    Exploit code for this vulnerability is publicly available.

    Impact

    By causing a Windows system to connect to a malicious SMB share, a remote attacker may be able to cause a denial of service by crashing Windows.

    Solution

    The CERT/CC is currently unaware of a practical solution to this problem. Please consider the following workarounds:

    Block outbound SMB

    Consider blocking outbound SMB connections (TCP ports 139 and 445 along with UDP ports 137 and 138) from the local network to the WAN.

    https://www.kb.cert.org/vuls/id/867968
    The Hackmaster
Working...
X