4 ms·
tl;dr: a null deref in windows kernel when you connect to a malicious SMB share
by pomfpomfpomf3 10y ago
tl;dr: a null deref in windows kernel when you connect to a malicious SMB share
- SlashmanX 10y agoThat's not what this article is about though really
- tokenizerrr 10y agoSure, but the main question I had when reading the headline was if I should go into "Oh shit!" mode.
- slowmotiony 10y agoThanks
- MohammadLee 10y agotl;dr: a CVSS 7.8 Windows vulnerability in the SMB service can allow an attacker to DoS any machine with the filesharing service exposed; the possibility of RCE seems to have been discarded; exploits are freely available online. This article complains that Microsoft's communication is lacking details and transparency in times of war
- j_s 10y agoYes, the vulnerability is client-side AFAIK. PoC GIF: https://twitter.com/vvalien1/status/826935182456418304 https://twitter.com/vvalien1/status/826935182456418304