CVE-2017-0269
published 2017-05-12CVE-2017-0269: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB…
PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
6.46%
93.0th percentile
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | server_block_message_1.0 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0269 [MEDIUM] CWE-20 GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
GHSA
GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0273 [MEDIUM] CWE-20 GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
GHSA
GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0280 [MEDIUM] CWE-20 GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
Microsoft
Windows SMB Denial of Service Vulnerability
vendor_msrc·2017-05-09·CVSS 7.0
CVE-2017-0269 [MEDIUM] Windows SMB Denial of Service Vulnerability
Windows SMB Denial of Service Vulnerability
Description: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server. An attacker who exploited this vulnerability could cause the affected system to stop responding until it is manually restarted. To attempt to exploit this issue, an attacker would need to send specially crafted SMB requests to the target system.
Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.
The security update addresses the vulnerability by correcting the manner in which SMB handles specially crafted client requests.
Windows SMB Server: Window
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/98263http://www.securitytracker.com/id/1038433https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269http://www.securityfocus.com/bid/98263http://www.securitytracker.com/id/1038433https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269
2017-05-12
Published