CVE

CVE-2006-2374

Severity:
MEDIUM
Type:
Unavailable / Other
Publication date:
13/06/2006
Last modified:
15/02/2024

Description

The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:itanium:*
cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_2003_server:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:-:sp1:*:*:*:*:itanium:*
cpe:2.3:o:microsoft:windows_xp:-:*:*:*:professional:*:x64:*
cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*