9.3
CVSSv2

CVE-2008-4037

Published: 12/11/2008 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 945
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server_2003

microsoft windows server 2008 -

microsoft windows xp

microsoft windows vista -

microsoft windows 2000 -

Exploits

########################################## # Exploit for "Authentication flaw in Windows SMB protocol" # ########################################## # Release Date: # April 24, 2003 # # Code by Haamed Gheibi (haamed@linuxceautacir) # Salman Niksefat (salman@linuxceautacir) # # Systems Affected by this exploit: # Windows 2000 (SP0 SP1 ...
* SMBRELAY 3 - NTLM replay attack (version 10 ) public version * (c) 2008 Andres Tarasco Acuña ( atarasco _at_ gmailcom ) * URL: tarascoorg/Web/toolshtml githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/7125zip (2008-smbrelay3zip) # milw0rmcom [2008-11-14] ...
## # $Id: smb_relayrb 10404 2010-09-21 00:13:30Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## =begin Windows XP systems that ...