peter bassill · operator
$ cve CVE-2006-2374 JSON

CVE-2006-2374 EXPLOIT

5.5
MEDIUM · CVSS 3.1 · EPSS 1.7% (pctl 77)

Patch early

A public exploit exists.

Description

The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS1.75% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-667
On CISA KEVno
Public exploityes
Published2006-06-13
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD