Vulnerability Name:
CVE-2017-0273 (CCN-125559)
Assigned:
2016-09-09
Published:
2017-05-09
Updated:
2018-03-28
Summary:
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from
CVE-2017-0269
and
CVE-2017-0280
.
CVSS v3 Severity:
5.9 Medium
(CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
)
5.2 Medium
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
5.9 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
)
5.2 Medium
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
CVSS v2 Severity:
4.3 Medium
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
5.4 Medium
(CCN CVSS v2 Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Complete
Vulnerability Type:
CWE-20
Vulnerability Consequences:
Denial of Service
References:
Source: MITRE
Type: CNA
CVE-2017-0273
Source: BID
Type: Third Party Advisory, VDB Entry
98274
Source: CCN
Type: BID-98274
Microsoft Windows SMB Server CVE-2017-0273 Remote Denial of Service Vulnerability
Source: SECTRACK
Type: UNKNOWN
1038433
Source: XF
Type: UNKNOWN
ms-smb-cve20170273-dos(125559)
Source: MISC
Type: UNKNOWN
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
Source: CCN
Type: Microsoft Security TechCenter
Security Update Guide - May 2017 Security Updates
Source: CONFIRM
Type: Mitigation, Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0273
Vulnerable Configuration:
Configuration 1
:
cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_10:1511:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_10:1607:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_10:1703:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*
OR
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*
OR
cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:*
OR
cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
OR
cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*
OR
cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:*
OR
cpe:/o:microsoft:windows_10:*:*:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
microsoft
windows 10 -
microsoft
windows 10 1511
microsoft
windows 10 1607
microsoft
windows 10 1703
microsoft
windows 7 * sp1
microsoft
windows 8.1 *
microsoft
windows server 2008 * sp2
microsoft
windows server 2008 r2 sp1
microsoft
windows server 2012 -
microsoft
windows server 2012 r2
microsoft
windows server 2016 -
microsoft
windows server 2008 sp2
microsoft
windows server 2008 sp2
microsoft
windows server 2008
microsoft
windows 7 - sp1
microsoft
windows 7 * sp1
microsoft
windows server 2008 r2
microsoft
windows server 2008 r2
microsoft
windows server 2012
microsoft
windows 8.1 - -
microsoft
windows 8.1 *
microsoft
windows server 2012 r2
microsoft
windows rt 8.1 *
microsoft
windows 10 -
microsoft
windows 10 *
microsoft
windows server 2016