CVE-2010-0270

Microsoft Windows 7 - Improper Input Validation

Title source: rule

Description

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."

Exploits (1)

exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/12273

Scores

EPSS 0.8139
EPSS Percentile 99.2%

Details

CWE
CWE-20
Status published
Products (2)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_server_2008 (2 CPE variants)
Published Apr 14, 2010
Tracked Since Feb 18, 2026