A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
Existe una vulnerabilidad de ejecución de código remota en la manera en que el protocolo Microsoft Server Message Block (SMBv3) versión 3.1.1, maneja determinadas peticiones, también se conoce como ''Windows SMBv3 Client/Server Remote Code Execution Vulnerability".
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-119
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-119
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60e846ddc0> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60e846d640> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e60eb227100> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e60eb226a00> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e60e846dc80> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e60e846df00> | Operating System |
| microsoft | windows_server_1903 | - | <built-in method update of dict object at 0x7e60bb915580> | Operating System |
| microsoft | windows_server_1909 | - | <built-in method update of dict object at 0x7e60bb917640> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:* |