2009-2532 | Microsoft Windows EducatedScholar code injection (BID-36594 / EDB-9594)
|CVSS Meta Temp Score||Current Exploit Price (≈)||CTI Interest Score|
A vulnerability has been found in Microsoft Windows (Operating System) (affected version unknown) and classified as very critical. Affected by this vulnerability is an unknown function. The manipulation with an unknown input leads to a privilege escalation vulnerability (EducatedScholar). The CWE definition for the vulnerability is CWE-94. As an impact it is known to affect confidentiality, integrity, and availability. The summary by CVE is:
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka “SMBv2 Command Value Vulnerability.”
The weakness was shared 10/14/2009 (Website). The advisory is shared at us-cert.gov. This vulnerability is known as CVE-2009-2532 since 07/17/2009. The exploitation appears to be easy. The attack can be launched remotely. The exploitation doesn’t need any form of authentication. Technical details are unknown but an exploit is available. The price for an exploit might be around USD $0-$5k at the moment (estimation calculated on 08/23/2021).
It is declared as proof-of-concept. It is possible to download the exploit at exploit-db.com. We expect the 0-day to have been worth approximately $25k-$100k. The vulnerability scanner Nessus provides a plugin with the ID 42106 , which helps to determine the existence of the flaw in a target environment. The commercial vulnerability scanner Qualys is able to test this issue with plugin 90527 (Microsoft Server Message Block (SMBv2) Remote Code Execution Vulnerability (MS09-050) and Shadow Brokers (EDUCATEDSCHOLAR)).
Upgrading eliminates this vulnerability. Furthermore it is possible to detect and prevent this kind of attack with TippingPoint and the filter 8649.
VulDB Meta Base Score: 10.0
VulDB Meta Temp Score: 9.5
NVD Base Score: 🔍
Class: Privilege escalation / EducatedScholar
0-Day Time: 🔍
10/13/2009 +88 days 🔍
10/14/2009 +1 days 🔍
10/14/2009 +0 days 🔍
10/14/2009 +0 days 🔍
03/18/2015 +1981 days 🔍
08/23/2021 +2350 days 🔍Vendor: https://www.microsoft.com/
Status: Not defined
Vulnerability Center: 23728 – [MS09-050] Microsoft Windows Vista and Server 2008 SMBv2 Remote Code Execution Vulnerability, Critical
See also: 🔍
Check our Alexa App!