← back
CVE-2009-2526observed exploitation

CVE-2009-2526

67Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 82%
from disclosure to weapon307 days
Published on NVDOct 14
1st PoC+307d
VulnCheck+2806d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.