CVE Vulnerabilities

CVE-2009-2526

Published: Oct 14, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka SMBv2 Infinite Loop Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Windows_server_2008Microsoft**
Windows_server_2008Microsoft- (including)- (including)
Windows_server_2008Microsoft–sp2 (including)–sp2 (including)
Windows_vistaMicrosoft**
Windows_vistaMicrosoft–sp1 (including)–sp1 (including)
Windows_vistaMicrosoft–sp2 (including)–sp2 (including)

References