Executive brief
A vulnerability in Windows NT causes the operating system to crash or freeze when processing specific file directory commands from a Samba client. This affects the availability of file shares and can lead to a complete system outage, disrupting business operations and access to shared data. An attacker or a misconfigured client can trigger this state by attempting to navigate to a parent directory on a network share.
Technical details
A denial-of-service vulnerability exists in Windows NT's handling of SMB/CIFS requests. When a Samba client connected to a Windows NT file share issues a 'change directory' command to the parent directory (cd ..), the operating system may encounter a kernel-level hang or crash. This is likely due to improper handling of directory traversal requests or malformed SMB packets originating from non-Windows SMB implementations. The attack can be triggered over the network without specific authentication if the share is accessible, resulting in a complete loss of system availability. Microsoft addressed this issue in legacy Knowledge Base article Q140818.
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed