Security ID : QSA-24-42

Vulnerability in SMB Service (PWN2OWN 2024)


  • Release date : October 30, 2024

  • CVE identifier : CVE-2024-50387

  • Affected products: SMB Service 4.15.x, SMB Service h4.15.x

Severity

Critical

Status

Resolved


Summary

A vulnerability has been reported to affect SMB Service.

  

We have already fixed the vulnerability in the following versions:

Affected Product Fixed Version
SMB Service 4.15.x SMB Service 4.15.002 and later
SMB Service h4.15.x SMB Service h4.15.002 and later

Recommendation

To fix the vulnerability, we recommend updating SMB Service to the latest version.

Updating SMB Service

  1. Log on to QTS or QuTS hero as an administrator.
  2. Open App Center and then click .
    A search box appears.
  3. Type "SMB Service" and then press ENTER.
    SMB Service appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your SMB Service is already up to date.
  5. Click OK.
    The system downloads the latest version.
  6. Open SMB Service.
    An update notice appears.
  7. Read the notice carefully.
  8. Select I acknowledge and accept the terms and conditions associated with updating the SMB Service.
  9. Click Update.
    The system updates the application.

    

Attachment

Acknowledgements: Pwn2Own 2024 - YingMuo working with DEVCORE Internship Program

Revision History:
V1.0 (October 30, 2024) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      back to top