CVE-2010-0477 Information
Share on:
Feb 14, 2021
cve
Description
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response and then improperly interact with the Winsock Kernel (WSK) aka \SMB Client Message Size Vulnerability.\
Reference
http://secunia.com/advisories/39372 http://www.us-cert.gov/cas/techalerts/TA10-103A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-020 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6859