Release DateOct 16, 2009 |
Severityhigh |
ImpactDenial of Service: Remote attackers can crash vulnerable systems. |
DescriptionThis indicates an attempt to exploit a denial of service vulnerability in Microsoft Server Message Block (SMB).The vulnerability is caused by an error that occurs when Microsoft Server Message Block (SMB) Protocol 2.0 software handles a malformed ioctl request. A remote attacker could exploit this vulnerability to crash the vulnerable system. |
Affected ProductsWindows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2 Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2 |
Recommended ActionsRefer to the vendor's web site for suggested workaround.http://www.microsoft.com/technet/security/Bulletin/ms09-050.mspx |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2009-2526 |
Reference/shttp://technet.microsoft.com/en-us/security/bulletin/ms09-050.mspx (MS-ID) |