peter bassill · operator
$ cve CVE-2009-2526 JSON

CVE-2009-2526 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 81.9% (pctl 100)

Patch early

A public exploit exists.

Description

Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS81.89% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2009-10-14
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftwindows server 2008
microsoftwindows vista

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD