New Remote Flaw Found in SMB2 in Windows Vista and Windows 7
Researchers have found a new vulnerability in the SMB2 protocol in Windows Vista and Windows 7 that enables an attacker to remotely crash vulnerable machines. There is proof-of-concept exploit available for the vulnerability, as well.
There is no patch available for the vulnerability, which affects fully updated machines running all versions of both 32-bit and 64-bit Windows Vista and Windows 7. SMB2 is a newer version of the venerable Server Message Block protocol. The suggested workaround for defeating the exploit is to disable SMB2 until a patch is available.
Editor's Pick
On Tuesday, Microsoft released an advisory on the SMB2 problem, confirming the vulnerability and saying that the issue with Windows 7 exists only in the Windows 7 Release Candidate and not in the Windows 7 RTM.
From the vulnerability bulletin:
SRV2.SYS fails to handle malformed SMB headers for the NEGOTIATE PROTOCOL REQUEST functionality.
The NEGOTIATE PROTOCOL REQUEST is the first SMB query a client send to a SMB server, and it's used to identify the SMB dialect that will be used for further communication.
In order for the attack to work, file sharing must be enabled on the target machine. The researcher who discovered the flaw, Laurent Gaffie, said that he has contacted Microsoft and notified them of the vulnerability. News of the flaw comes on the monthly Patch Tuesday for Microsoft, a day on which the company will be releasing five critical fixes for its products.
SMB2 was designed by Microsoft as a more efficient and modern version of the original SMB protocol, which was designed by IBM. SMB is used for sharing resources such as printers, files and ports across a network.
Commenting on this Article is closed.
Today's Most Popular
- Researchers Discover Android Mobile Botnet 100k Strong
- Phony Temple Run Game For Android Plays On Android-iOS App Gap
- Adobe's Security Chief Talks About Driving Up The Cost of Exploits
- Hackers Hit Alabama, Mexican Government Websites
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (8)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (56)
-
Did Apple, RIM and Nokia Help The Indian Government Spy On The U.S.? (3)
-
Google Begins Security Review Process for Android Apps (2)
-
Costin Raiu on the Timing of the Duqu Attacks (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




