Microsoft Windows S.M.B. Client Transaction Response Remote-Code-Execution Vulnerability

On Tuesday April 13, 2010, Patches for a Vulnerability in Microsoft's S.M.B. client on Windows 7 and Windows Server 2008 were made available. If exploited, this Vulnerability could allow an attacker to gain full access to the affected system. On April 19, 2010, a proof-of-concept for the vulnerability was made Publicly Available. To Exploit this vulnerability, an attacker would have to entice a user into accessing a malicious S.M.B. Server.

Users that have not yet Applied the Patch are urge to apply the patch as soon as possible.

Information about the Vulnerability can be found at:

 

- Vulnerabilities in S.M.B. Client Could Allow Remote-Code Execution (980232).

 

- Microsoft Windows S.M.B. Client Transaction Response Remote-Code-Execution Vulnerability.

 

The Proof-Of-Concept is at:

 

- M.S.10-020.