Hacker News new | ask | show | jobs
by pomfpomfpomf3 3418 days ago
tl;dr: a null deref in windows kernel when you connect to a malicious SMB share
4 comments

tl;dr: a CVSS 7.8 Windows vulnerability in the SMB service can allow an attacker to DoS any machine with the filesharing service exposed; the possibility of RCE seems to have been discarded; exploits are freely available online. This article complains that Microsoft's communication is lacking details and transparency in times of war
That's not what this article is about though really
Sure, but the main question I had when reading the headline was if I should go into "Oh shit!" mode.
Yes, the vulnerability is client-side AFAIK.

PoC GIF: https://twitter.com/vvalien1/status/826935182456418304

Thanks