CVE-2010-0017

Microsoft Windows 7 - Race Condition

Title source: rule

Description

Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by laurent gaffie · pythondoswindows
https://www.exploit-db.com/exploits/12258
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/smb/ms10_006_negotiate_response_loop.rb

Scores

EPSS 0.4393
EPSS Percentile 97.5%

Details

CWE
CWE-362
Status published
Products (4)
microsoft/windows_7
microsoft/windows_server_2008 (5 CPE variants)
microsoft/windows_server_2008 r2
microsoft/windows_vista (4 CPE variants)
Published Feb 10, 2010
Tracked Since Feb 18, 2026