The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
El servidor SMBv1 en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; y Windows 10 Gold, 1511 y 1607; y Windows Server 2016 permite a atacantes remotos ejecutar código arbitrario a través de paquetes manipulados, vulnerabilidad también conocida como "Windows SMB Remote Code Execution Vulnerability". Esta vulnerabilidad es diferente a la descrita en CVE-2017-0143, CVE-2017-0144, CVE-2017-0146 y CVE-2017-0148.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | server_message_block | 1.0 | <built-in method update of dict object at 0x7e60a88a9b00> | Application |
| siemens | acuson_p300_firmware | 13.02 | <built-in method update of dict object at 0x7e60a88aa240> | Operating System |
| siemens | acuson_p300_firmware | 13.03 | <built-in method update of dict object at 0x7e6107f3b240> | Operating System |
| siemens | acuson_p300_firmware | 13.20 | <built-in method update of dict object at 0x7e613c3d55c0> | Operating System |
| siemens | acuson_p300_firmware | 13.21 | <built-in method update of dict object at 0x7e60a88a9ac0> | Operating System |
| siemens | acuson_p500_firmware | va10 | <built-in method update of dict object at 0x7e60a88a9a00> | Operating System |
| siemens | acuson_p500_firmware | vb10 | <built-in method update of dict object at 0x7e60a88abe00> | Operating System |
| siemens | acuson_sc2000_firmware | * | <built-in method update of dict object at 0x7e6107f38bc0> | Operating System |
| siemens | acuson_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60a88abcc0> | Operating System |
| siemens | acuson_x700_firmware | 1.0 | <built-in method update of dict object at 0x7e60a88abc40> | Operating System |
| siemens | acuson_x700_firmware | 1.1 | <built-in method update of dict object at 0x7e60eb225900> | Operating System |
| siemens | syngo_sc2000_firmware | * | <built-in method update of dict object at 0x7e61109d41c0> | Operating System |
| siemens | syngo_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60a88aa500> | Operating System |
| siemens | tissue_preparation_system_firmware | * | <built-in method update of dict object at 0x7e60eb225380> | Operating System |
| siemens | versant_kpcr_molecular_system_firmware | * | <built-in method update of dict object at 0x7e60a88ab240> | Operating System |
| siemens | versant_kpcr_sample_prep_firmware | * | <built-in method update of dict object at 0x7e6107f38200> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:* |