The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability".
http://www.securityfocus.com/bid/101140
http://www.securitytracker.com/id/1039528
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11781
Source: MITRE
Published: 2017-10-13
Updated: 2017-10-20
Type: CWE-20
Base Score: 7.8
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
Impact Score: 6.9
Exploitability Score: 10
Severity: HIGH
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
104384 | KB4042895: Windows 10 October 2017 Cumulative Update (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103876 | Microsoft Windows SMB Server (2017-10) Multiple Vulnerabilities (uncredentialed check) | Nessus | Windows | medium |
103816 | Windows 2008 October 2017 Multiple Security Updates (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103750 | Windows 8.1 and Windows Server 2012 R2 October 2017 Security Updates (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103749 | KB4041691: Windows 10 Version 1607 and Windows Server 2016 October 2017 Cumulative Update (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103748 | Windows Server 2012 October 2017 Security Updates (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103747 | KB4041689: Windows 10 Version 1511 October 2017 Cumulative Update (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103746 | Windows 7 and Windows Server 2008 R2 October 2017 Security Updates (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |
103745 | KB4041676: Windows 10 Version 1703 October 2017 Cumulative Update (KRACK) | Nessus | Windows : Microsoft Bulletins | critical |