Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-17051

Опубликовано: 10 нояб. 2020
Источник: msrc
CVSS3: 9.8
EPSS Средний

Описание

Windows Network File System Remote Code Execution Vulnerability

FAQ

What is the attack vector for this vulnerability?

In a network-based attack an attacker with write access to an NFS share could execute code remotely within the kernel.

Is this CVE wormable?

This CVE is wormable between machines hosting writable NFS shares.

Where should the customer be applying the update?

The vulnerability only exists in Windows NFS Servers.

Обновления

ПродуктСтатьяОбновление
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

Older Software Release

Exploitation More Likely

DOS

N/A

EPSS

Процентиль: 94%
0.14901
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Windows Network File System Remote Code Execution Vulnerability

CVSS3: 9.8
github
около 3 лет назад

Windows Network File System Remote Code Execution Vulnerability

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость файловой системы NTFS операционной системы Windows, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 94%
0.14901
Средний

9.8 Critical

CVSS3