Microsoft Patches Leaked Remote Code Execution Flaw

  /     /     /  
Publicated : 23/11/2024   Category : security


Microsoft Patches Leaked Remote Code Execution Flaw


A vulnerability in Microsofts Server Message Block protocol prompted concerns of wormable exploits when it was disclosed this week.



Microsoft has patched a critical remote code execution vulnerability in its Server Message Block (SMBv3) protocol and is urging organizations to deploy updates for the flaw as soon as possible.
CVE-2020-0796 exists in the way SMBv3 handles certain requests. An attacker who successfully exploits the flaw can gain complete control over a vulnerable system and execute arbitrary code within the context of the application. To exploit this vulnerability against an SMB server, an unauthenticated attacker could send a specially crafted packet to a target SMBv3 server. To exploit it against an SMB client, they would need to configure a malicious SMBv3 server and convince a user to connect, Microsoft officials wrote in a Patch Tuesday
advisory
.
This vulnerability was not part of Microsofts monthly patch roundup; the company did not explain why. Its advisory was posted after details were
inadvertently
released and there was no patch available, which prompted concerns of a wormable exploit. The advisory advised businesses to disable SMBv3 compression to defend systems from unauthenticated intruders.
Todays patch, issued in a tight turnaround after the advisory was published, fixes the problem by correcting how the SMBv3 protocol handles the specially crafted requests an attacker would use to exploit the vulnerability. There has so far been no evidence this flaw has been exploited in the wild; however, Microsoft notes that exploitation is more likely.
Read more details
here
.
Check out
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays featured story:
Keys to Hiring Cybersecurity Pros When Certification Cant Help
.

Last News

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security

▸ Criminal Possession of Government-Grade Stealth Malware ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Microsoft Patches Leaked Remote Code Execution Flaw