本文讲的是
SMB v3远程拒绝服务漏洞分析,
漏洞简介
0: kd> !analyze -v FAULTINGIP: mrxsmb20!Smb2ValidateNegotiateInfo+17 fffff80e847fd117 66394114 cmp word ptr [rcx+14h],ax rax=0000000000000001 rbx=0000000000000000 rcx=0000000000000000 rdx=ffff9a0e216adb20 rsi=0000000000000000 rdi=0000000000000000 rip=fffff80e847fd117 rsp=fffff8020385bec0 rbp=ffff9a0e21530ae8 r8=0000000000000001 r9=0000000000000000 r10=ffff9a0e218d2b20 r11=fffff8020385c1a8 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei ng nz na po nc mrxsmb20!Smb2ValidateNegotiateInfo+0x17: fffff80e847fd117 66394114 cmp word ptr [rcx+14h],ax ds:00000000`00000014=???? FOLLOWUPNAME: MachineOwner MODULENAME: mrxsmb20 IMAGENAME: mrxsmb20.sys OSPLATFORMTYPE: x64 OSNAME: Windows 10 BUILDOSVERSTR: 10.0.14393.447.amd64fre.rs1releaseinmarket.161102-0100
原文发布时间为:2017年2月10日
本文作者:四叶草安全
本文来自云栖社区合作伙伴嘶吼,了解相关信息可以关注嘶吼网站。