CVE-2008-4037

Scores

EPSS

0.755medium75.5%
0%20%40%60%80%100%

Percentile: 75.5%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka “SMB Credential Reflection Vulnerability.” NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-287

Exploits

Exploit ID: 16360

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16360

Exploit ID: 20

Source: exploitdb

URL: https://www.exploit-db.com/exploits/20

Exploit ID: 7125

Source: exploitdb

URL: https://www.exploit-db.com/exploits/7125

Vulnerable Software (4)

Type: Configuration

Vendor: microsoft

Product: windows

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:s...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: windows_2000

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:s...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: windows_server_2008

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:s...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: windows_vista

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:microsoft:windows:server_2003:s...

Source: nvd