Oval Definition:oval:org.mitre.oval:def:6012
Revision Date:2014-03-03Version:25
Title:SMB Credential Reflection Vulnerability
Description:Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-4037
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):
Definition Synopsis
  • Check for Vulnerable Windows 2000 SP4 and Mrxsmb.sys version
  • Microsoft Windows 2000 SP4 or later is installed
  • AND Mrxsmb.sys version is less than 5.0.2195.7174
  • OR Check for Vulnerable Windows XP (x86) SP2 and Mrxsmb.sys version
  • Microsoft Windows XP (x86) SP2 is installed
  • AND Mrxsmb.sys version is less than 5.1.2600.3467
  • OR Check for Vulnerable Windows XP (x86) SP3 and Mrxsmb.sys version
  • Microsoft Windows XP (x86) SP3 is installed
  • AND Mrxsmb.sys version is less than 5.1.2600.5700
  • OR Check for Vulnerable Windows Server 2003 SP1 (x64)/(x86)/(ia-64)/Windows XP Professional SP1 (x64) and Mrxsmb.sys version
  • Check for Vulnerable Windows Server 2003 SP1 (x64)/(x86)/(ia-64)/Windows XP Professional SP1 (x64)
  • Microsoft Windows Server 2003 SP1 (x64) is installed
  • OR Microsoft Windows XP Professional x64 Edition SP1 is installed
  • OR Microsoft Windows Server 2003 SP1 (x86) is installed
  • OR Microsoft Windows Server 2003 SP1 for Itanium is installed
  • AND Mrxsmb.sys version is less than 5.2.3790.3206
  • OR Check for Vulnerable Windows Server 2003 SP2 (x64)/(x86)/(ia-64)Windows XP Professional SP2 (x64)and Mrxsmb.sys version
  • Check for Vulnerable Windows Server 2003 SP2 (x64)/(x86)/(ia-64)/Windows XP Professional SP2 (x64)
  • Microsoft Windows Server 2003 SP2 (x64) is installed
  • OR Microsoft Windows XP x64 Edition SP2 is installed
  • OR Microsoft Windows Server 2003 SP2 (x86) is installed
  • OR Microsoft Windows Server 2003 (ia64) SP2 is installed
  • AND Mrxsmb.sys version is less than 5.2.3790.4369
  • OR Check for Vulnerable Windows Vista(x64)/Vista(x86) and Mrxsmb10.sys version
  • Check for Vulnerable Windows Vista(x64)/Vista(x86)
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • AND Check for LDR/GDR
  • Check for GDR
  • Mrxsmb10.sys version is less than 6.0.6000.16738
  • OR Check for LDR
  • Mrxsmb10.sys version is greater than or equal 6.0.6000.20000
  • AND Mrxsmb10.sys version is less than 6.0.6000.20904
  • OR Check for Vulnerable Windows Vista (32-bit)SP1/x64 SP1/Server 2008 (32-bit)/(64-bit)/(ia-64) and Mrxsmb10.sys version
  • Check for Vulnerable Windows Vista (32-bit)SP1/x64 SP1/Server 2008 (32-bit)/(64-bit)/(ia-64)
  • Microsoft Windows Vista (32-bit) Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Check for LDR/GDR
  • Check for GDR
  • Mrxsmb10.sys version is less than 6.0.6001.18130
  • OR Check for LDR
  • Mrxsmb10.sys version is greater than or equal 6.0.6001.22000
  • AND Mrxsmb10.sys version is less than 6.0.6001.22252
  • BACK