← All CVEs

CVE-2008-4037

high · 9.3

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

9.3
CVSS
59.1%
EPSS (exploit prob.)
99th
EPSS percentile
2008-11-12
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
microsoftwindowsserver_2003
microsoftwindowsserver_2003
microsoftwindowsserver_2003
microsoftwindowsserver_2003
microsoftwindowsserver_2003
microsoftwindowsserver_2003
microsoftwindowsxp
microsoftwindowsxp
microsoftwindowsxp
microsoftwindowsxp
microsoftwindows_2000all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008all versions
microsoftwindows_vistaall versions
microsoftwindows_vistaall versions
microsoftwindows_vistaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-4037