Endpoint Vulnerability

Microsoft: Windows SMB Remote Code Execution Vulnerability

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server. To exploit the vulnerability, in most situations, an authenticated attacker could send a specially crafted packet to a targeted SMBv2 server. The security update addresses the vulnerability by correcting how SMBv2 handles these specially crafted requests.

Affected Products

Windows RT 8.1,Windows Server, version 1709 (Server Core Installation),Windows Server 2016,Windows Server, version 1803 (Server Core Installation),Windows Server 2012,Windows 8,Windows Server 2008,Windows 10,Windows 7,Windows Server 2019

References

CVE-2019-0630,