Description: A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an improper implementation of SMBv2 signing and can be exploited to execute arbitrary code by spoofing the signature in a SMBv2 packet to a trusted host.
Successful exploitation requires e.g. that SMBv2 is enabled (not enabled by default unless required by a host) and that SMBv2 is used in the communications (not used when e.g. one system is a previous operating system version).
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.