>> Microsoft Windows Vista SMBv2 Signing Remote Vulnerability (MS07-063)
Title : Microsoft Windows Vista SMBv2 Signing Remote Vulnerability (MS07-063) VUPEN ID : VUPEN/ADV-2007-4179 CVE ID : CVE-2007-5351
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-11
Technical Description
A vulnerability has been identified in Microsoft Windows Vista, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by an error in the Server Message Block (SMB) version 2 implementation, which could be exploited by anonymous remote attackers to modify an SMBv2 packet and re-compute the signature to run code with the privileges of the logged-on user.
Note : SMB signing is disabled by default in Windows Vista.