CVE-2017-11781Improper Input Validation in Corporation Server Block Message

Severity
7.5HIGHNVD
OSV5.3
EPSS
21.8%
top 4.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 17

Description

The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages16 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-54h5-qvh3-364q: The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 82022-05-17
OSV
spamassassin vulnerabilities2018-11-06

📋Vendor Advisories

1
Microsoft
W - SMB - DOS Authenticated2017-10-10

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - October 20172017-10-10