header-logo
Suggest Exploit
vendor:
Windows
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows
Affected Version From: Windows 95/98
Affected Version To: Windows 95/98
Patch Exists: NO
Related CWE: Unknown
CPE: o:microsoft:windows_95
Metasploit:
Other Scripts:
Platforms Tested: Windows
Unknown

Windows SMB Service Buffer Overflow

The SMB service within Windows 95/98 allocates 0x400*4 bytes to store file handles. Therefore, a file handle returned to a client will be in the range 0 - 1023. When SMB commands such as SMBfindclose are sent to the service specifying a specially crafted handle out of that range, the sharing service will attempt to access illegal memory address. Successful exploitation of this vulnerability will cause the sharing service to buffer overflow and likely crash.

Mitigation:

Unknown
Source

Exploit-DB raw data: