CVE-2017-0274Sensitive Information Exposure in Corporation Microsoft Server Message Block 1.0

Severity
5.9MEDIUMNVD
EPSS
15.6%
top 5.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 14

Description

Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0275, and CVE-2017-0276.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages15 packages

Patches

🔴Vulnerability Details

7
GHSA
GHSA-gx4h-c9f9-cjmg: Microsoft Server Message Block 12022-05-14
GHSA
GHSA-mwpj-4jmh-82qc: Microsoft Server Message Block 12022-05-14
GHSA
GHSA-p7c6-mmr9-2fxj: Microsoft Server Message Block 12022-05-14
GHSA
GHSA-m5q7-66rc-v2x4: Microsoft Server Message Block 12022-05-14
GHSA
GHSA-6chx-2m5j-vcqc: Microsoft Server Message Block 12022-05-14

📋Vendor Advisories

1
Microsoft
Windows SMB Information Disclosure Vulnerability2017-05-09

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - May 20172017-05-10
Talos
Vulnerability Spotlight: ARM Mbedtls x509 ECDSA invalid public key Code Execution Vulnerability2017-04-19
Talos
Vulnerability Spotlight: ARM Mbedtls x509 ECDSA invalid public key Code Execution Vulnerability2017-04-19

💬Community

1
Bugzilla
CVE-2017-2784 mbedtls: ARM Mbedtls x509 ECDSA invalid public key use-after-free2017-04-19