The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
El servidor SMBv1 en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; y Windows 10 Gold, 1511 y 1607; y Windows Server 2016 permite a atacantes remotos obtener información sensible de la memoria del proceso a través de paquetes manipulados, vulnerabilidad también conocida como "Windows SMB Information Disclosure Vulnerability".
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
AV:N/AC:M/Au:N/C:P/I:N/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_10_1507 | - | <built-in method update of dict object at 0x7e60e884b040> | Operating System |
| microsoft | windows_10_1511 | - | <built-in method update of dict object at 0x7e6112e72c80> | Operating System |
| microsoft | windows_10_1607 | - | <built-in method update of dict object at 0x7e6110d40cc0> | Operating System |
| microsoft | windows_7 | - | <built-in method update of dict object at 0x7e6107bccf80> | Operating System |
| microsoft | windows_8.1 | - | <built-in method update of dict object at 0x7e60e8848580> | Operating System |
| microsoft | windows_rt_8.1 | - | <built-in method update of dict object at 0x7e60e8849680> | Operating System |
| microsoft | windows_server_2008 | - | <built-in method update of dict object at 0x7e60b8463a80> | Operating System |
| microsoft | windows_server_2008 | r2 | <built-in method update of dict object at 0x7e6110d406c0> | Operating System |
| microsoft | windows_server_2012 | - | <built-in method update of dict object at 0x7e60bbd1b040> | Operating System |
| microsoft | windows_server_2012 | r2 | <built-in method update of dict object at 0x7e60e884a400> | Operating System |
| microsoft | windows_server_2016 | - | <built-in method update of dict object at 0x7e6110d40540> | Operating System |
| microsoft | windows_vista | - | <built-in method update of dict object at 0x7e613c173600> | Operating System |
| siemens | acuson_p300_firmware | 13.02 | <built-in method update of dict object at 0x7e60a8d28a00> | Operating System |
| siemens | acuson_p300_firmware | 13.03 | <built-in method update of dict object at 0x7e6110d43980> | Operating System |
| siemens | acuson_p300_firmware | 13.20 | <built-in method update of dict object at 0x7e6110d41f40> | Operating System |
| siemens | acuson_p300_firmware | 13.21 | <built-in method update of dict object at 0x7e60a8d2ab00> | Operating System |
| siemens | acuson_p500_firmware | va10 | <built-in method update of dict object at 0x7e60e884b1c0> | Operating System |
| siemens | acuson_p500_firmware | vb10 | <built-in method update of dict object at 0x7e6110d438c0> | Operating System |
| siemens | acuson_sc2000_firmware | * | <built-in method update of dict object at 0x7e60b8460500> | Operating System |
| siemens | acuson_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e6112e766c0> | Operating System |
| siemens | acuson_x700_firmware | 1.0 | <built-in method update of dict object at 0x7e60a8d297c0> | Operating System |
| siemens | acuson_x700_firmware | 1.1 | <built-in method update of dict object at 0x7e62aa3d0e40> | Operating System |
| siemens | syngo_sc2000_firmware | * | <built-in method update of dict object at 0x7e6110d41740> | Operating System |
| siemens | syngo_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60bbd1a780> | Operating System |
| siemens | tissue_preparation_system_firmware | * | <built-in method update of dict object at 0x7e6110d408c0> | Operating System |
| siemens | versant_kpcr_molecular_system_firmware | * | <built-in method update of dict object at 0x7e60a8d29bc0> | Operating System |
| siemens | versant_kpcr_sample_prep_firmware | * | <built-in method update of dict object at 0x7e60bb3610c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:* |