Exploitation Summary
CVE-2009-2526 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits.
AI-analyzed exploit summary This exploit targets a vulnerability in Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference, allowing remote code execution on Vista SP1/SP2 systems. It spawns a reverse shell on port 28876, granting SYSTEM-level access.
Description
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
Exploits (2)
This exploit targets a vulnerability in Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference, allowing remote code execution on Vista SP1/SP2 systems. It spawns a reverse shell on port 28876, granting SYSTEM-level access.
This exploit targets CVE-2009-2526, a vulnerability in Microsoft Windows SMBv2. It crafts a malicious SMB packet to trigger a buffer overflow, followed by a reverse shell payload. The exploit requires authentication to trigger the payload execution.