SMB: Microsoft Windows SMBv1 NT_TRANSACT_IOCTL Remote Code Execution
This signature detects attempts to exploit a known vulnerability against Microsoft Windows SMBv1 NT_TRANSACT_IOCTL. A successful attack can lead to arbitrary code execution.
Extended Description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
Affected Products
Microsoft windows_server_2016
References
CVE: CVE-2020-1301
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
6.5