{"id":"CVE-2009-3103","aliases":[],"url":"https://o3.security/vulnerability/CVE-2009-3103","summary":"Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers…","details":"Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka \"SMBv2 Negotiation Vulnerability.\" NOTE: some of these details are obtained from third party information.","published":"2009-09-08T22:30:00.517","modified":"2026-06-16T23:10:57.120","cvss":null,"epss":{"score":0.90227,"percentile":0.99787,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":13,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0090.html"},{"type":"WEB","url":"http://blog.48bits.com/?p=510"},{"type":"EXPLOIT","url":"http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html"},{"type":"WEB","url":"http://isc.sans.org/diary.html?storyid=7093"},{"type":"WEB","url":"http://osvdb.org/57799"},{"type":"ADVISORY","url":"http://secunia.com/advisories/36623"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/9594"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/135940"},{"type":"ADVISORY","url":"http://www.microsoft.com/technet/security/advisory/975497.mspx"},{"type":"WEB","url":"http://www.reversemode.com/index.php?option=com_content&task=view&id=64&Itemid=1"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/506300/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/506327/100/0/threaded"},{"type":"EXPLOIT","url":"http://www.securityfocus.com/bid/36299"},{"type":"WEB","url":"http://www.securitytracker.com/id?1022848"},{"type":"WEB","url":"http://www.us-cert.gov/cas/techalerts/TA09-286A.html"},{"type":"WEB","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-050"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53090"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6489"},{"type":"EXPLOIT","url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0090.html"},{"type":"WEB","url":"http://blog.48bits.com/?p=510"},{"type":"EXPLOIT","url":"http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html"},{"type":"WEB","url":"http://isc.sans.org/diary.html?storyid=7093"},{"type":"WEB","url":"http://osvdb.org/57799"},{"type":"ADVISORY","url":"http://secunia.com/advisories/36623"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/9594"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/135940"},{"type":"ADVISORY","url":"http://www.microsoft.com/technet/security/advisory/975497.mspx"},{"type":"WEB","url":"http://www.reversemode.com/index.php?option=com_content&task=view&id=64&Itemid=1"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/506300/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/506327/100/0/threaded"},{"type":"EXPLOIT","url":"http://www.securityfocus.com/bid/36299"},{"type":"WEB","url":"http://www.securitytracker.com/id?1022848"},{"type":"WEB","url":"http://www.us-cert.gov/cas/techalerts/TA09-286A.html"},{"type":"WEB","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-050"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53090"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6489"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:10:57.120"}}