Information Disclosure Vulnerability in Microsoft Windows SMB Implementation
CVE-2010-0231

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
10 February 2010

What is CVE-2010-0231?

The SMB implementation in certain Microsoft Windows products fails to utilize a secure source of entropy. As a result, remote attackers can exploit this weakness through numerous authentication requests. This exploitation may lead to unauthorized access to sensitive files and SMB resources by manipulating server-generated challenges, utilizing duplicate values, and spoofing authentication tokens. This vulnerability highlights significant security risks associated with inadequate entropy in authentication processes.

References

EPSS Score

51% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.