CVE-2017-0280
published 2017-05-12CVE-2017-0280: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
7.17%
93.6th percentile
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| conversejs | converse.js | >= 0 < 1.0.7 | 1.0.7 |
| conversejs | converse.js | >= 2.0.0 < 2.0.5 | 2.0.5 |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | server_block_message_1.0 | — | — |
| movim | moxl | 0.8 – 0.10 | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| sleekxmpp_project | sleekxmpp | >= 0 < 1.3.2 | 1.3.2 |
| slixmpp_project | slixmpp | >= 0 < 1.2.4 | 1.2.4 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
XMPP Clients User Impersonation Vulnerability in Movim Moxl
ghsa·2022-05-17
CVE-2017-5605 [MEDIUM] CWE-20 XMPP Clients User Impersonation Vulnerability in Movim Moxl
XMPP Clients User Impersonation Vulnerability in Movim Moxl
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Movim 0.8 - 0.10.
GHSA
GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0269 [MEDIUM] CWE-20 GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
GHSA
GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0273 [MEDIUM] CWE-20 GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
GHSA
GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0280 [MEDIUM] CWE-20 GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
GHSA
SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons
ghsa·2022-05-13
CVE-2017-5591 [MEDIUM] CWE-940 SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons
SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.
GHSA
User Impersonation in converse.js
ghsa·2020-09-11
CVE-2017-5858 [MEDIUM] CWE-20 User Impersonation in converse.js
User Impersonation in converse.js
Versions of `converse.js` prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of [XEP-0280: Message Carbons](https://xmpp.org/extensions/xep-0280.html) that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
## Recommendation
If you're using `converse.js` 1.x, upgrade to 1.0.7 or later.
If you're using `converse.js` 2.x, upgrade to 2.0.5 or later.
Microsoft
Windows SMB Denial of Service Vulnerability
vendor_msrc·2017-05-09·CVSS 7.0
CVE-2017-0280 [MEDIUM] Windows SMB Denial of Service Vulnerability
Windows SMB Denial of Service Vulnerability
Description: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server. An attacker who exploited this vulnerability could cause the affected system to stop responding until it is manually restarted. To attempt to exploit this issue, an attacker would need to send specially crafted SMB requests to the target system.
Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.
The security update addresses the vulnerability by correcting the manner in which SMB handles specially crafted client requests.
Windows SMB Server: Window
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - May 2017
blogs_talos·2017-05-10·CVSS 7.5
CVE-2017-0290 [HIGH] Microsoft Patch Tuesday - May 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.
In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.
## Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft:
- CVE-2017-0221
- CVE-2017-0222
- CV
Bugzilla
CVE-2017-5593 psi-plus: User impersonation vulnerability
bugzilla·2017-02-10·CVSS 5.9
CVE-2017-5593 [MEDIUM] CVE-2017-5593 psi-plus: User impersonation vulnerability
CVE-2017-5593 psi-plus: User impersonation vulnerability
An incorrect implementation of XEP-0280: Message Carbons[0] in psi-plus client allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
References:
http://seclists.org/oss-sec/2017/q1/373
Upstream patch:
https://github.com/psi-im/iris/pull/47/commits/02e976d4426a1319a7af7d26d7aba9d8c6077570
Discussion:
Created psi-plus tracking bugs for this issue:
Affects: epel-7 [bug 1421070]
Affects: fedora-all [bug 1421071]
---
psi-plus in Fedora hasn't carbon feature.
Bugzilla
CVE-2017-5591 python-sleekxmpp: User impersonation vulnerability
bugzilla·2017-02-10·CVSS 5.9
CVE-2017-5591 [MEDIUM] CVE-2017-5591 python-sleekxmpp: User impersonation vulnerability
CVE-2017-5591 python-sleekxmpp: User impersonation vulnerability
An incorrect implementation of XEP-0280: Message Carbons[0] in psi-plus client allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
References:
http://seclists.org/oss-sec/2017/q1/373
http://www.securityfocus.com/bid/98273https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0280http://www.securityfocus.com/bid/98273https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0280
2017-05-12
Published