漏洞描述 Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Microsoft Windows XP SP2和SP3,以及Server 2003 SP2的分布式文件系统(DFS)客户端在分析特制DFS响应时存在远程代码执行漏洞。远程攻击者可以通过将特制的DFS响应发送到客户端发起的DFS请求,导致执行任意代码,并可完全控制受影响的系统。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完全用户权限的新帐户。
相关漏洞推荐 POC sharepoint-lists-api-disclosure: Microsoft SharePoint - List API Disclosure POC CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure POC sharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure POC sharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure POC sharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata Disclosure POC sharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass Windows PolicyConfiguration 计划任务特权提升漏洞(CVE-2025-60710) Windows 11 PolicyConfiguration 计划任务特权提升漏洞(CVE-2025-60710) Windows 11 RAiLaunchAdminProcess 管理员保护特权提升漏洞 (CVE-2025-62522)Vite开发服务器Windows环境下文件泄露漏洞 (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行 (CVE-2025-41246) VMware Tools for Windows授权不当漏洞