Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2018-0833: Windows Denial of Service Vulnerability

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Microsoft CVE-2018-0833: Windows Denial of Service Vulnerability

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:N/I:N/A:C)
Published
02/13/2018
Created
07/25/2018
Added
02/13/2018
Modified
08/21/2019

Description

A denial of service vulnerability exists in implementations of the Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client. The vulnerability is due to improper handling of certain requests sent by a malicious SMB server to the client. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding until it is manually restarted. To exploit the vulnerability, an attacker could use various methods such as redirectors, injected HTML header links, etc., which could cause the SMB client to connect to a malicious SMB server. The security update addresses the vulnerability by correcting how the Microsoft SMBv2/SMBv3 Client handles specially crafted requests.

Solution(s)

  • msft-kb4074597-e23ec185-3ead-4c5c-bd1e-a9058cc7c06b
  • msft-kb4074597-ef515c36-d5d5-4d6d-8413-fdced1c51834
  • msft-kb4074597-f5df629a-edb7-49f1-946d-18e4f0a860f0

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;