CVE-2020-17051: Remote kernel heap overflow in NFSv3 Windows Server
ID: dd865fe3-cf64-52b0-bebb-a43f05d39f55
STIX ID: report--dd865fe3-cf64-52b0-bebb-a43f05d39f55
Feed Name: McAfee Labs Blog
**Executive Summary:** Microsoft released a patch for CVE-2020-17051, a critical (CVSS 9.8) vulnerability in the Windows NFSv3 server (nfssvr.sys) that can trigger immediate BSOD and enable remote code execution; combined with CVE-2020-17056 (remote kernel data read/ASLR bypass) the vulnerabilities increase likelihood of remote exploitation and potential worm-like spread via writable NFS shares. The advisory notes affected configurations (authenticated or anonymous write access), cites ~38,893 hosts with port 2049 reachable, and recommends patching, limiting NFS write access, blocking external access, and using McAfee NSP signatures as a virtual patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
