vendor:
Windows 8.1
by:
Nabeel Ahmed
5.3
CVSS
MEDIUM
Denial of Service
416
CWE
Product Name: Windows 8.1
Affected Version From: SMBv3
Affected Version To: SMBv3
Patch Exists: YES
Related CWE: CVE-2018-0833
CPE: o:microsoft:windows_8.1
Other Scripts:
N/A
Platforms Tested: Windows 8.1 (x86), Windows Server 2012 R2 (x64)
2018
Microsoft Windows SMB Client Null Pointer Dereference Denial of Service
This exploit triggers a Blue Screen of Death (BSoD) on the target machine by sending a specially crafted payload to the SMBv3 service. The payload contains a null pointer dereference which causes the system to crash.
Mitigation:
Microsoft has released a patch for this vulnerability in the March 2018 Patch Tuesday.