New Search

Windows SMB Remote Code Execution Vulnerability - CVE-2019-0630

oval:org.cisecurity:def:5980

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server. To exploit the vulnerability in most situations an authenticated attacker could send a specially crafted packet to a targeted SMBv2 server. The security update addresses the vulnerability by correcting how SMBv2 handles these specially crafted requests.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2008
  • Microsoft Windows 8.1
  • Microsoft Windows 7
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2019-0630
  • MSRC-CVE-2019-0630
  • KB4486564
  • KB4487019
  • KB4486993
  • KB4487028
  • KB4487018
  • KB4487026
  • KB4487020
  • KB4486996
  • KB4487017
  • KB4487044
Product(s):