HomeinetZero-Day in Windows 8, 10: Check your system

Zero-Day in Windows 8, 10: Check your system

The United States Computer Emergency Readiness Team (US-CERT) has published a new zero-day that affects Microsoft Windows 8, 10, and Server operating systems.

US-CERT reports:

Microsoft Windows contains a memory corruption bug in its handling of SMB traffic, which could allow a remote, unauthenticated attacker to cause a denial of service or potentially execute arbitrary code on a vulnerable system.Zero Day

Attackers using this zero-day could cause denial of service (DoS) attacks against versions of Windows that contain the bug. This would allow vulnerable devices to connect to malicious SMBs. US-CERT says there is a possibility that the vulnerability could also be exploited to execute arbitrary code with Windows Core privileges.

The vulnerability description provides additional information:

Windows fails to properly handle traffic from a malicious server. Specifically, Windows fails to properly handle a server response that contains too many bytes following the structure defined by the SMB2 TREE_CONNECT Response. By connecting to a malicious SMB server, the vulnerable Windows system may experience a BSOD (Blue Screen of Death) with a Mrxsmb20.sys error. It is unclear at this point whether this vulnerability can be exploited beyond a denial-of-service attack. We have confirmed the crash with fully patched Windows 10 and Windows 8.1 client systems.

US-CERT confirmed the vulnerability in fully patched Windows 8.1 and Windows 10 client systems. Bleeping Computer reports that security researcher PythonResponder claims that the vulnerability also affects Windows Server 2012 and 2016.

At present, there is no official confirmation that Windows Servers are also affected by the vulnerability.

US-CERT rates the vulnerability at the highest severity rating (10), and it's worth noting that Microsoft has not released a security update yet.

US-CERT on the other hand recommends blocking all outbound SMB connections on TCP port 139 and 445, and UDP 137 and 138 from the local network to the WAN.

To find out if the version of Windows you're using has any SMB connections, do the following:

  • In the search, type Powershell, right-click on the icon and open as administrator.
  • Confirm the UAC that will appear
  • and run the Get-SmbConnection command.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS