Executive brief
A vulnerability exists in systems using NetBIOS or SMB file sharing where share-level passwords are weak or easily guessable. This allows an unauthorized person to gain access to shared files and folders over the network. Such access could lead to the theft of sensitive company data or the modification of important files.
Technical details
This vulnerability involves the use of weak, default, or easily guessable passwords for NetBIOS/SMB shares. The root cause is typically a lack of password complexity requirements or the use of share-level security (common in older Windows versions) rather than user-level security. An unauthenticated attacker on the network can use brute-force or dictionary attacks to guess the password. Successful exploitation grants the attacker the same permissions as the share's intended users, potentially allowing for unauthorized reading, writing, or deletion of files. Mitigation involves enforcing strong password policies and migrating to more secure authentication protocols.
Affected products
- Multiple Windows (various) / Samba / NetBIOS-compatible OS
Timeline
- 1997-01-01: disclosed