>> Microsoft Windows SMB Credential Reflection Vulnerability (MS08-068)
Title : Microsoft Windows SMB Credential Reflection Vulnerability (MS08-068) VUPEN ID : VUPEN/ADV-2008-3110 CVE ID : CVE-2008-4037 CWE ID : CWE-287
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-11
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an error in the Server Message Block (SMB) protocol does not properly validate NTLM authentication replies, which could be exploited by remote attackers to trick a user into connecting to a specially crafted server share or Web site, and replay the user's credentials back to them, leading to remote code execution.