vendor:
Windows
by:
Laurent GaffiƩ
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Windows
Affected Version From: Windows 7/2008R2
Affected Version To: Windows 7/2008R2
Patch Exists: YES
Related CWE: CVE-2010-0270
CPE: o:microsoft:windows_7:-:
Platforms Tested: Windows 7/2008R2
2010
Windows 7/2008R2 SMB Client Trans2 stack overflow (MS10-020)
This exploit takes advantage of a stack overflow vulnerability in the SMB client of Windows 7/2008R2. By sending a specially crafted packet, an attacker can overwrite the EBP and EIP registers, allowing for arbitrary code execution. The vulnerability is tracked as CVE-2010-0270.
Mitigation:
Apply the patch provided by Microsoft in MS10-020 to fix this vulnerability. Additionally, ensure that all systems are kept up to date with the latest security patches.