CVE-2009-3103 (CNNVD-200909-131)
中文标题:
Microsoft Windows Vista和Windows 7畸形SMB报文远程拒绝服务漏洞
英文标题:
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, ...
漏洞描述
中文描述:
Windows是微软发布的非常流行的操作系统。 Windows Vista捆绑了新版的SMB2,SRV2.SYS驱动没有正确地处理发送给NEGOTIATE PROTOCOL REQUEST功能的畸形SMB头,如果远程攻击者在发送的SMB报文的Process Id High头字段中包含有"&"字符的话,就会在_Smb2ValidateProviderCallback()函数中触发越界内存引用,导致执行任意代码或系统蓝屏死机。
英文描述:
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | windows_server_2008 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | sp2 | - | - |
cpe:2.3:o:microsoft:windows_server_2008:sp2:x32:*:*:*:*:*:*
|
| microsoft | windows_vista | * | - | - |
cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
cve.org
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
CVSS评分详情
AV:N/AC:L/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2009-3103 |
2025-11-11 15:18:11 | 2025-11-11 07:33:03 |
| NVD | nvd_CVE-2009-3103 |
2025-11-11 14:53:00 | 2025-11-11 07:41:50 |
| CNNVD | cnnvd_CNNVD-200909-131 |
2025-11-11 15:09:06 | 2025-11-11 07:49:38 |
| EXPLOITDB | exploitdb_EDB-10005 |
2025-11-11 15:05:50 | 2025-11-11 08:00:23 |
| EXPLOITDB | exploitdb_EDB-12524 |
2025-11-11 15:05:50 | 2025-11-11 08:04:47 |
| EXPLOITDB | exploitdb_EDB-14674 |
2025-11-11 15:05:57 | 2025-11-11 08:08:22 |
| EXPLOITDB | exploitdb_EDB-16363 |
2025-11-11 15:05:57 | 2025-11-11 08:10:59 |
| EXPLOITDB | exploitdb_EDB-40280 |
2025-11-11 15:05:57 | 2025-11-11 08:40:08 |
| EXPLOITDB | exploitdb_EDB-9594 |
2025-11-11 15:05:50 | 2025-11-11 09:06:45 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 31 -> 33
- tags_count: 10 -> 11
查看详细变更
- references_count: 29 -> 31
- tags_count: 9 -> 10
查看详细变更
- references_count: 27 -> 29
- tags_count: 8 -> 9
查看详细变更
- references_count: 23 -> 27
- tags_count: 5 -> 8
查看详细变更
- references_count: 21 -> 23
- tags_count: 4 -> 5
查看详细变更
- references_count: 18 -> 21
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-200909-131
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 10.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']