CVE-2009-3103
HIGH 10.0EPSS 90.2%
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 90.23% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2009-09-08
- Updated
- 2024-08-07
Proof-of-concept exploits (8)
- http://www.exploit-db.com/exploits/9594
- http://www.securityfocus.com/archive/1/506327/100/0/threaded
- Sic4rio/CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050-4★ · 2024-05-05
- ankh2054/python-exploits73★ · 2021-01-26
- joshchalabi/SMBv2-Exploit-PrivEsc2★ · 2025-06-10
- sec13b/ms09-050_CVE-2009-31030★ · 2024-05-03
- afifudinmtop/CVE-2009-3103
- nicolasdamians/ms09-050-CVE-2009-3103-exploit
Metasploit modules (1)
ExploitDB entries (6)
- https://www.exploit-db.com/exploits/16363
- https://www.exploit-db.com/exploits/12524
- https://www.exploit-db.com/exploits/10005
- https://www.exploit-db.com/exploits/9594
- https://www.exploit-db.com/exploits/40280
- https://www.exploit-db.com/exploits/14674