The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
El servidor SMBv1 en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; y Windows 10 Gold, 1511 y 1607; y Windows Server 2016 permite a atacantes remotos ejecutar código arbitrario a través de paquetes manipulados, vulnerabilidad también conocida como "Windows SMB Remote Code Execution Vulnerability". Esta vulnerabilidad es diferente a la descrita en CVE-2017-0143, CVE-2017-0145, CVE-2017-0146 y CVE-2017-0148.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | server_message_block | 1.0 | <built-in method update of dict object at 0x7e60e832fb00> | Application |
| siemens | acuson_p300_firmware | 13.02 | <built-in method update of dict object at 0x7e60e832d980> | Operating System |
| siemens | acuson_p300_firmware | 13.03 | <built-in method update of dict object at 0x7e6112303880> | Operating System |
| siemens | acuson_p300_firmware | 13.20 | <built-in method update of dict object at 0x7e6107f3ac00> | Operating System |
| siemens | acuson_p300_firmware | 13.21 | <built-in method update of dict object at 0x7e60e832df40> | Operating System |
| siemens | acuson_p500_firmware | va10 | <built-in method update of dict object at 0x7e60e832d9c0> | Operating System |
| siemens | acuson_p500_firmware | vb10 | <built-in method update of dict object at 0x7e60e832d840> | Operating System |
| siemens | acuson_sc2000_firmware | * | <built-in method update of dict object at 0x7e60e832cec0> | Operating System |
| siemens | acuson_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60eb226b40> | Operating System |
| siemens | acuson_x700_firmware | 1.0 | <built-in method update of dict object at 0x7e60e832eb80> | Operating System |
| siemens | acuson_x700_firmware | 1.1 | <built-in method update of dict object at 0x7e60e832e500> | Operating System |
| siemens | syngo_sc2000_firmware | * | <built-in method update of dict object at 0x7e6134108340> | Operating System |
| siemens | syngo_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60e832d6c0> | Operating System |
| siemens | tissue_preparation_system_firmware | * | <built-in method update of dict object at 0x7e60eb225740> | Operating System |
| siemens | versant_kpcr_molecular_system_firmware | * | <built-in method update of dict object at 0x7e60e832fb40> | Operating System |
| siemens | versant_kpcr_sample_prep_firmware | * | <built-in method update of dict object at 0x7e60e832d240> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* |
| No | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* |
| No | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:* |
| No | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x86:* |
| No | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* |
| No | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* |
| No | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:* |