CVE Database
/

CVE-2008-4037

Back to search

CVE-2008-4037

Published: Nov 12, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

VendorProductVersions

n/a

n/a

affected
n/a

References

SSRT080164
vendor-advisory
x_refsource_HP
TA08-316A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:6012
vdb-entry
signature
x_refsource_OVAL
49736
vdb-entry
x_refsource_OSVDB
1021163
vdb-entry
x_refsource_SECTRACK
HPSBST02386
vendor-advisory
x_refsource_HP
ADV-2008-3110
vdb-entry
x_refsource_VUPEN
MS08-068
vendor-advisory
x_refsource_MS
32633
third-party-advisory
x_refsource_SECUNIA
7385
vdb-entry
x_refsource_BID
7125
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now