Vulnerability record · CVE-2009-2532 · published 14 October 2009
CVE-2009-2532: Windows SMBv2 command value handling allows remote code execution
Microsoft · Windows Server 2008
Windows Vista, Server 2008 and Windows 7 RC fail to properly process the command value in an SMB Multi-Protocol Negotiate Request packet. A remote attacker can send a crafted SMBv2 packet to the Server service and execute arbitrary code. The flaw is remotely reachable over the network with no authentication required.
Description
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network-reachable, unauthenticated remote code execution and a very high EPSS percentile warrants critical handling despite no KEV listing.
What it is
Windows Vista, Server 2008 and Windows 7 RC fail to properly process the command value in an SMB Multi-Protocol Negotiate Request packet. A remote attacker can send a crafted SMBv2 packet to the Server service and execute arbitrary code. The flaw is remotely reachable over the network with no authentication required.
Impact
An unauthenticated remote attacker can execute arbitrary code with system-level privileges on the affected host, leading to full compromise of the target.
Attack surface
Reached over the network via the SMB Server service (port 445) using a crafted SMBv2 negotiate packet; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is 0.62171 (99.1st percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS09-050 to affected Windows Vista, Server 2008 and Windows 7 RC systems.
- Disable SMBv2 where it is not required, or block SMB (TCP 445) at network boundaries and between untrusted segments.
- Restrict SMB exposure to trusted internal networks and enforce host firewall rules limiting inbound 445 access.
- Monitor vendor guidance and retire or upgrade unsupported Windows 7 RC and Vista builds that cannot be patched.
Detection
- Inspect SMBv2 negotiate traffic for malformed or unexpected command values in Multi-Protocol Negotiate Request packets.
- Alert on SMB Server service crashes or unexpected restarts on affected hosts.
- Hunt for anomalous outbound connections or process creation following SMB service activity on Vista/Server 2008/Windows 7 RC systems.
- Review network flow logs for inbound TCP 445 from untrusted sources to affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-2532 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.