Es wurde eine kritische Schwachstelle in vorgenommen. Auswirkungen sind zu beobachten für die Verfügbarkeit.
Am 02.06.2017 wurde das Problem entdeckt. Die Schwachstelle wurde am 26.07.2017 durch Sean Dillon und Zach Harding (Website) via DEF CON 25 publik gemacht. Das Advisory kann von ). Historisch interessant ist diese Schwachstelle mitunter wegen ihrer speziellen Ausprägung. Das Advisory weist darauf hin:
The NetBIOS Session Service (NBSS) header is the initial TCP data transmitted to start an SMB session, and is processed before any authentication mechanism is ever established. It occupies 4 bytes of memory. Windows immediately commits in memory a number of bytes determined by the attacker-controlled Length field, which is 217 for a max of 131,072 bytes (128 KiB). This memory is in the "non-paged pool" (physical RAM) which cannot be swapped out to disk, making the denial of service even more effective. CPU and memory resources are effectively lost for as long as the connection is sustained.Ein öffentlicher Exploit wurde durch Hector Martin in ANSI C umgesetzt und 1 Wochen nach dem Advisory veröffentlicht. Er wird als funktional gehandelt. Der Download des Exploits kann von ) dokumentiert. Weitere Informationen werden unter
CVSSv3
VulDB Base Score:VulDB Vector:
CVSSv2
VulDB Base Score:VulDB Zuverlässigkeit: High
Researcher Base Score:
Exploiting
Klasse: Denial of Service / Smbloris (Preisentwicklung: gleichbleibend
Aktuelle Preisschätzung: $0-$5k (0-day) / $0-$5k (Heute)
Gegenmassnahmen
Empfehlung: FirewallStatus: Workaround
0-Day Time: 54 Tage seit gefunden
Exploit Delay Time: 7 Tage seit bekannt
Firewalling: 139/445 (smb)
Timeline
02.06.2017 Schwachstelle gefunden03.06.2017
31.07.2017
08.08.2017
Quellen
Advisory:Diverses: community.rapid7.com
Eintrag
Erstellt: 08.08.2017Eintrag: 88% komplett
SOCIAL SHARE CARD GENERATOR