CVE-2009-3103 is a remote vulnerability in the SMBv2 protocol implementation in Microsoft Windows, specifically in srv2.sys on Windows Vista, Windows Server 2008, and pre-release Windows 7 builds identified in the available reporting. The flaw is an array index error triggered during processing of an SMBv2 NEGOTIATE PROTOCOL REQUEST. A specially crafted request containing an ampersand character in the Process ID High header field can cause the kernel component to dereference an out-of-bounds memory location. Successful exploitation can result in arbitrary code execution in kernel context or a system crash. The issue is commonly referred to as the SMBv2 Negotiation Vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This eight-file Python repository is a standalone exploit tool for CVE-2009-3103 (MS09-050), an unauthenticated SMBv2 srv2.sys vulnerability affecting legacy Microsoft Windows Vista and Windows Server 2008 releases. MS09.py is the command-line entry point and provides scan and exploit modes. lib/scanner.py performs SMB negotiation over TCP/445, identifies SMBv2 support, attempts OS fingerprinting through SMB session setup data, infers architecture, and labels Vista/Server 2008 signatures as vulnerable or potentially vulnerable. lib/exploit.py constructs the malformed SMB negotiate buffer with architecture-specific return addresses and stagers, sends it to the target, and invokes rpcclient to provoke an SMB authentication event intended to trigger the injected payload. lib/payloads.py patches LHOST/LPORT into an x86 Meterpreter reverse-TCP stager; users can instead load arbitrary raw shellcode or invoke local msfvenom for selectable x86/x64 payloads. lib/output.py supplies display helpers. The code is an active network RCE exploit rather than a scanner-only or fake repository. Although it is not itself a Metasploit module, it integrates with Metasploit tooling and accepts customizable payloads, making it weaponized. Notable implementation caveats are heuristic vulnerability/architecture detection, the use of socket.send rather than sendall, and hard-coded callback values (192.168.1.1:443) within the included x64 stager constant.
Repository contains a single Python exploit script (exploit.py) and a short README. The exploit targets CVE-2009-3103 by generating a Metasploit payload via msfvenom (default windows/shell/reverse_tcp, configurable via CLI), embedding the resulting raw shellcode into a prebuilt SMB buffer that includes a hardcoded return address and a Metasploit stager (commented as stager_sysenter_hook), and sending the crafted packet directly to the target’s SMB service on TCP/445. After delivery, it attempts to trigger execution by running rpcclient against the target (Administrator user, dummy password) to invoke an RPC command (getusername). The README provides basic operational steps: scan with nmap smb-vuln scripts, start a Metasploit handler, then run the Python script with target IP and listener parameters. Overall purpose: remote code execution attempt against vulnerable Windows SMB/RPC stack, resulting in a reverse shell/Meterpreter session back to the attacker.
This repository provides an automated Bash script (ms09_050.sh) that streamlines exploitation of the MS09-050 (CVE-2009-3103) vulnerability in Microsoft Windows Vista SP1/SP2 and Windows Server 2008 (pre-R2) systems. The script takes a target IP, attacker's IP, and optional port, then generates a Python exploit (exploit.py) and a Metasploit handler resource file (handler.rc). The exploit.py script, when run, sends a specially crafted SMBv2 packet containing msfvenom-generated reverse shellcode to the target's port 445. The handler.rc file is used to launch a Metasploit handler to catch the reverse shell. The repository is structured for ease of use, requiring minimal manual intervention, and is intended for penetration testing and OSCP exam preparation. The main exploit vector is network-based, targeting SMBv2 over TCP port 445. No hardcoded IPs or domains are present; all endpoints are user-supplied at runtime.
This repository contains a single Metasploit module implementing a remote kernel-mode exploit for the MS09-050 (CVE-2009-3103) vulnerability in the Microsoft SRV2.SYS SMB driver. The exploit targets Windows Vista SP1/SP2 and Windows Server 2008 (x86) systems running vulnerable versions of the SMB2 service. The module crafts a specially designed SMB negotiation packet to trigger an out-of-bounds function table dereference, resulting in kernel-mode code execution. The exploit is highly weaponized, leveraging Metasploit's payload system to deliver arbitrary shellcode (such as Meterpreter) to the target. The only fingerprintable endpoint is TCP port 445, which must be accessible for the attack to succeed. The code is written in Ruby and is structured as a standard Metasploit exploit module, with all logic contained in a single file. The module is not suitable for automated exploitation due to reliability concerns, as noted in the code comments.
This repository contains a single Metasploit auxiliary module targeting the Microsoft SRV2.SYS SMB driver vulnerability (CVE-2009-3103, also known as MS09-050). The exploit is a denial-of-service (DoS) attack that sends a specially crafted SMB negotiation packet to a target Windows system (Vista, 7 pre-RTM, or 2008 Server pre-R2) over TCP port 445. The crafted packet manipulates the ProcessIDHigh field to trigger an out-of-bounds function table dereference, causing the target system to crash. The module allows the user to specify the function table offset, which could potentially be used for further research into code execution, but as provided, the exploit only causes a crash and does not achieve remote code execution. The code is written in Ruby and is structured as a standard Metasploit module, with options for the target port and offset. The included comments provide detailed information about possible offsets for different Windows versions, which may assist in further exploitation or research.
This repository contains a single Metasploit auxiliary module that exploits a denial-of-service vulnerability (CVE-2009-3103) in the Microsoft SRV2.SYS kernel driver, affecting Windows Vista SP1/SP2 and Windows Server 2008 SP1/SP2. The exploit works by sending a specially crafted SMB2 logoff request to the target's SMB service (TCP port 445) before a session is negotiated, triggering a NULL pointer dereference and causing a system crash (BSOD). The module is written in Ruby and is structured as a typical Metasploit auxiliary DoS module, with options for specifying the target host and port. No payload is delivered beyond the malformed SMB2 request, and the exploit does not provide post-exploitation capabilities. The code is operational as a proof-of-concept for denial of service and is not weaponized for further compromise.
This repository contains a Python exploit script (MS09-050.py) and a README.md. The exploit targets the Microsoft Windows 'srv2.sys' SMB vulnerability (CVE-2009-3103, also known as MS09-050). The script takes a target IP address as input and crafts a malicious SMB packet containing custom shellcode (by default, a reverse shell generated with msfvenom, but customizable). It connects to the target's SMB service on port 445, sends the exploit buffer, and then triggers the payload via an RPC call using 'rpcclient'. The README provides background, usage instructions, and credits. The exploit is operational, providing remote code execution on vulnerable Windows systems. The main attack vector is network-based, targeting the SMB service. The only code file is MS09-050.py, which is the entry point for the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.