vendor:
Windows
by:
ohnozzy
9,3
CVSS
HIGH
SMBv2 Remote Code Execution Vulnerability
78
CWE
Product Name: Windows
Affected Version From: Windows 7/Server 2008 R2
Affected Version To: Windows XP/Server 2003
Patch Exists: YES
Related CWE: CVE-2009-3103
CPE: o:microsoft:windows
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
MS09_050
This exploit is a python script which uses the SMBv2 protocol to inject a malicious payload into the target system. The payload is a reverse TCP shell which connects back to the attacker's machine. The exploit first sends a packet containing the payload to the target system, and then triggers the payload by attempting to authenticate with the target system.
Mitigation:
Disable SMBv2 protocol on the target system.