Samba SMB1 message_push_string Information Disclosure (CVE-2017-15275)

An information disclosure vulnerability exists in the SMB1 component of Samba. The vulnerability is due to the inclusion of uninitialized memory in certain responses. A remote, authenticated attacker could exploit this vulnerability by sending maliciously crafted SMB1 commands to the target server. Successful exploitation could result in the disclosure of memory from the target system.

from Check Point Update Services Advisories http://ift.tt/2DLnwgY

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...