CVE-2006-2374
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
- Affected products
- Windows, Server Message Block
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2003 Server
- All versions
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-667
- NVD status
- Modified
- Published
- 2006-06-13
CVE-2006-2374 at NVD
2 known exploits for CVE-2006-2374
Proof-of-concept code and exploit modules indexed by Sploitus