CVE-2009-2526
67Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 82%
from disclosure to weapon307 days
Published on NVDOct 14
1st PoC+307d
VulnCheck+2806d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/40280unverifiedexploitdbwww.exploit-db.com/exploits/14674unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.