RULE(RULE ID:1905723)

Rule General Information
Release Date: 2018-08-08
Rule Name: SMB Null Pointer Dereference PoC Inbound Vulnerability (CVE-2018-0833)
Severity:
CVE ID:
Rule Protection Details
Description: The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:102924
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0833
SecurityTrackerID:1040375
https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2018-0833
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0833