Home / bulletins MS09-050 - Critical: Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517) - Version:1.1
Posted on 15 October 2009
There is an newer version: MS09-050 - Version: 1.0
CriticalSeverity Rating: Critical - Revision Note: V1.1 (October 14, 2009): Clarified the entry, "When this security bulletin was issued, had Microsoft received any reports that this vulnerability was being exploited?" in the section, FAQ for SMBv2 Negotiation Vulnerability - CVE-2009-3103.Summary: This security update resolves one publicly disclosed and two privately reported vulnerabilities in Server Message Block Version 2 (SMBv2). The most severe of the vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB packet to a computer running the Server service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate from outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.
Other versions
- MS09-050 - Version: 1.1
- MS09-050 - Version: 1.0