CVE-2018-0833
Microsoft Windows SMB Client Improper Initialization Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".
El cliente Microsoft Server Message Block 2.0 y 3.0 (SMBv2/SMBv3) en Windows 8.1 y RT 8.1 y Windows Server 2012 R2 permite una vulnerabilidad de denegaciĆ³n de servicio (DoS) debido a la forma en la que se gestionan las peticiones especialmente manipuladas. Esto tambiĆ©n se conoce como "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".
This vulnerability allows remote attackers to deny service to vulnerable installations of Microsoft Windows. In some cases, user interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file, but attack vectors may vary depending on the implementation.
The specific flaw exists within the mrxsmb.sys driver. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to deny access to the target system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-01 CVE Reserved
- 2018-02-15 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102924 | Third Party Advisory | |
http://www.securitytracker.com/id/1040375 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44189 | 2024-09-17 | |
https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2018-0833 | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0833 | 2019-03-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 8.1 Search vendor "Microsoft" for product "Windows 8.1" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Rt 8.1 Search vendor "Microsoft" for product "Windows Rt 8.1" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2012 Search vendor "Microsoft" for product "Windows Server 2012" | r2 Search vendor "Microsoft" for product "Windows Server 2012" and version "r2" | - |
Affected
|