Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New SMB bug: How to crash Windows system with a 'link of death'
The Register ^ | 2/3/17 | Thomas Claburn

Posted on 02/03/2017 7:53:50 PM PST by markomalley

US CERT on Thursday issued a security advisory warning that all currently supported versions of Windows are vulnerable to a memory corruption bug that can be exploited to crash computers from afar.

"Windows fails to properly handle a specially-crafted server response that contains too many bytes following the structure defined in the SMB2 TREE_CONNECT Response structure," the security organization said. "By connecting to a malicious SMB server, a vulnerable Windows client system may crash (BSOD) in mrxsmb20.sys."

The vulnerability was initially rated 10 out of 10 in terms of severity, but has since been downgraded to 7.8. To make use of the vulnerability, an attacker would have to get the Windows system to connect to a malicious SMB share.

This can be done by tricking a victim into clicking on a malicious link to a share in an email in Outlook, or by embedding in a webpage an invisible image with a source URL to an evil file server and getting the mark to visit the site using Internet Explorer, for example. The result is a blue-screen-of-death system crash out of nowhere for the poor user.

Security researcher Laurent Gaffié in an email told The Register that the bug involves a null-pointer dereference. He said that both Microsoft and he consider it a potential means to conduct a remote denial of service attack, but not a means to execute code remotely.

He said the bug can be used to make a target reboot either locally, via Netbios or LLMNR poisoning, or remotely via a UNC link.

"It's important to note that this trivial bug should have been caught immediately by [Microsoft's] SDLC process, but surprisingly it was not," Gaffié said. "This mean that the new code base was simply not audited or fuzzed before shipping it on their latest operating systems."

Gaffié said he submitted the bug to Microsoft on September 25, 2016, and that Microsoft had a patch ready for its December patch cycle. The company pushed the fix back to February, he explained, because it made more sense to them to released several SMB fixes at once rather than a single one in December.

As other security researchers have done, Gaffié said he decided to release the bug a week before the patch because this isn't the first time Microsoft has sat on vulnerabilities he's reported, enough though he's doing work to help the company for free.

"When they sit on a bug like this one, they're not helping their users but doing marketing damage control, and opportunistic patch release," he said. "This attitude is wrong for their users, and for the security community at large."

Gaffié has released a proof-of-concept exploit through GitHub. ®


TOPICS: Computers/Internet
KEYWORDS: security; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-23 next last
If you have Win10, be forewarned...
1 posted on 02/03/2017 7:53:50 PM PST by markomalley
[ Post Reply | Private Reply | View Replies]

To: markomalley

Downloaded windows 10. Big mistake. Will not open Edge and says “Woops. We can’t get there from here!”


2 posted on 02/03/2017 8:00:49 PM PST by Ruy Dias de Bivar
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

“Gaffié said he decided to release the bug a week before the patch ...”

Why release it at all?


3 posted on 02/03/2017 8:01:20 PM PST by nuconvert ( Khomeini promised change too // Hail, Chairman O)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; markomalley

Ping


4 posted on 02/03/2017 8:02:01 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nuconvert
Why release it at all?

Because without that pressure, M$ wouldn't bother fixing anything.

5 posted on 02/03/2017 8:02:40 PM PST by markomalley (Nothing emboldens the wicked so greatly as the lack of courage on the part of the good -- Leo XIII)
[ Post Reply | Private Reply | To 3 | View Replies]

To: markomalley

My head is spinning trying to read this. . .I’m still plodding away using Windows 7. . . .any hope for me?


6 posted on 02/03/2017 8:03:18 PM PST by Maudeen (No one on this earth is too far gone for Jesus.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maudeen
.any hope for me?

Yes.

https://linuxmint.com/

7 posted on 02/03/2017 8:04:46 PM PST by markomalley (Nothing emboldens the wicked so greatly as the lack of courage on the part of the good -- Leo XIII)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Maudeen

I clicked on a European Bulgarian yogurt link the other day that crashed me 3 times, without even the courtesy of the BSOD, just re-boots. Another link did the same a couple weeks ago.


8 posted on 02/03/2017 8:06:40 PM PST by txhurl (The LEFT are screaming at the Tsunami, and the Sky, trying to set fire to the Ocean- S.Tom)
[ Post Reply | Private Reply | To 6 | View Replies]

To: markomalley
"This attitude is wrong for their users, and for the security community at large."

What else is new? Microsoft doesn't give a damn about their customers, or what they need and want.

Same old, same old.

9 posted on 02/03/2017 8:13:44 PM PST by Windflier (Pitchforks and torches ripen on the vine. Left too long, they become black rifles.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maudeen
I’m still plodding away using Windows 7. . . .any hope for me?

Don't 'upgrade' to Windows 10.

Your Windows 7 system is the best OS Microsoft ever designed. Hold onto it until they rip it from your cold dead fingers.

10 posted on 02/03/2017 8:16:03 PM PST by Windflier (Pitchforks and torches ripen on the vine. Left too long, they become black rifles.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Windflier

Thanks. . .your post made me feel better.


11 posted on 02/03/2017 8:23:41 PM PST by Maudeen (No one on this earth is too far gone for Jesus.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Windflier; Maudeen
... all currently supported versions of Windows are vulnerable...
12 posted on 02/03/2017 8:37:33 PM PST by 867V309 (Lock Her Up)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Maudeen

Here is a pic of a guy using Windows 7
http://nynerd.com/wp-content/uploads/2007/03/microsoft-tech-support.jpg

Or what Microsoft wants you to think so you move to the future and use Windows 10..........


13 posted on 02/03/2017 10:32:17 PM PST by minnesota_bound
[ Post Reply | Private Reply | To 6 | View Replies]

To: minnesota_bound

Thanks. . .I needed that :)


14 posted on 02/03/2017 10:42:37 PM PST by Maudeen (No one on this earth is too far gone for Jesus.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: markomalley

Windows is a virus, and has been for years. People tolerate it, and learn to live with it because, unless you go Apple or Linux with their own quirks and idiosyncrasies, windows is still the only game in town for many applications. So people put up with its bullshit, but the fact remains that it’s been a crappy buggy error-prone operating system for decades. Microsoft spread itself too thin, and instead of producing a world class OS, they offer a myriad of products of dubious quality.


15 posted on 02/04/2017 7:24:54 AM PST by SpaceBar
[ Post Reply | Private Reply | To 1 | View Replies]

To: SpaceBar

That’s why I refer to them as the “Trolls of Redmond”.


16 posted on 02/04/2017 10:27:53 AM PST by DuncanWaring (The Lord uses the good ones; the bad ones use the Lord.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Maudeen

I had too many issues with Windows 10 along with it’s spyware and moved back to Windows 7.

Customize Windows 7

Stardock
http://www.stardock.com/products

WindowBlinds
http://www.stardock.com/products/windowblinds

Wincustomize
http://www.wincustomize.com


17 posted on 02/04/2017 10:33:15 AM PST by minnesota_bound
[ Post Reply | Private Reply | To 14 | View Replies]

To: markomalley

The people who create these “bugs” need to be found and made to wish that there was a death penalty for their transgressions. Unheated cell, thin blanket, loud acid rock-rap-Islamic call to prayer (whichever appears to offend the individual most) playing 24-7, bread and water, nowhere to sit or lie down...


18 posted on 02/04/2017 10:37:35 AM PST by JimRed ( TERM LIMITS, now and forever! Building the Wall, NOW!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound

Thanks


19 posted on 02/04/2017 11:08:15 AM PST by Maudeen (No one on this earth is too far gone for Jesus.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Swordmaker; markomalley; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; ...
Windows networking share bug (SMB) ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker for the ping!!

20 posted on 02/05/2017 6:25:39 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 4 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-23 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson