CVE-2009-2532
EXPLOITEDMicrosoft Windows Server 2008 - Code Injection
Title source: ruleDescription
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
Exploits (2)
References (3)
Scores
EPSS
0.6178
EPSS Percentile
98.3%
Details
VulnCheck KEV
2017-06-20
CWE
CWE-94
Status
published
Products (2)
microsoft/windows_server_2008
(8 CPE variants)
microsoft/windows_vista
(6 CPE variants)
Published
Oct 14, 2009
Tracked Since
Feb 18, 2026