VulnerabilityModified
CVE-2017-0269
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability".
MEDIUM 5.9EPSS 6.46%
Does this matter?
Lower severity and a low EPSS score (6.46%). Track it; it rarely justifies an emergency change on its own.
Description
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.46% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/windows 10 · microsoft/windows 7 · microsoft/windows 8.1 · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows server 2016
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/98263Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038433
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98263Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038433
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.