The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
El servidor SMBv1 en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; y Windows 10 Gold, 1511 y 1607; y Windows Server 2016 permite a atacantes remotos ejecutar código arbitrario a través de paquetes manipulados, vulnerabilidad también conocida como "Windows SMB Remote Code Execution Vulnerability". Esta vulnerabilidad es diferente a la descrita en CVE-2017-0143, CVE-2017-0144, CVE-2017-0145 y CVE-2017-0146.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-20
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-20
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | server_message_block | 1.0 | <built-in method update of dict object at 0x7e611206c340> | Application |
| siemens | acuson_p300_firmware | 13.02 | <built-in method update of dict object at 0x7e60eb26ea40> | Operating System |
| siemens | acuson_p300_firmware | 13.03 | <built-in method update of dict object at 0x7e60eb26f5c0> | Operating System |
| siemens | acuson_p300_firmware | 13.20 | <built-in method update of dict object at 0x7e60b8100740> | Operating System |
| siemens | acuson_p300_firmware | 13.21 | <built-in method update of dict object at 0x7e611206cc80> | Operating System |
| siemens | acuson_p500_firmware | va10 | <built-in method update of dict object at 0x7e611206f2c0> | Operating System |
| siemens | acuson_p500_firmware | vb10 | <built-in method update of dict object at 0x7e60eb26e000> | Operating System |
| siemens | acuson_sc2000_firmware | * | <built-in method update of dict object at 0x7e60eb26fb80> | Operating System |
| siemens | acuson_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60eb26cbc0> | Operating System |
| siemens | acuson_x700_firmware | 1.0 | <built-in method update of dict object at 0x7e611206e980> | Operating System |
| siemens | acuson_x700_firmware | 1.1 | <built-in method update of dict object at 0x7e60e832ea80> | Operating System |
| siemens | syngo_sc2000_firmware | * | <built-in method update of dict object at 0x7e60bb8863c0> | Operating System |
| siemens | syngo_sc2000_firmware | 5.0a | <built-in method update of dict object at 0x7e60eb26cac0> | Operating System |
| siemens | tissue_preparation_system_firmware | * | <built-in method update of dict object at 0x7e6106847d40> | Operating System |
| siemens | versant_kpcr_molecular_system_firmware | * | <built-in method update of dict object at 0x7e6106845640> | Operating System |
| siemens | versant_kpcr_sample_prep_firmware | * | <built-in method update of dict object at 0x7e60eb26ca00> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| No | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:* |