ZeroHour

CVE-2017-0144

KEV ransomware PoC ×6mass

Remote Code Execution in Microsoft SMBv1 (EternalBlue) affecting Windows and Siemens devices

CISA: Microsoft SMBv1 Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2017-0144 is a remote code execution flaw in the SMBv1 server component of Microsoft Windows, commonly known as EternalBlue, and one of the SMB flaws fixed by Microsoft in the March 2017 MS17-010 bulletin. An attacker who can reach the SMB service over the network sends specially crafted packets that trigger memory corruption in the SMBv1 implementation, gaining the ability to execute arbitrary code on the target without user interaction. Successful exploitation yields full system compromise and has been heavily weaponized for wormable spread and ransomware delivery, notably via the leaked NSA exploit and in the WannaCry/NotPetya-era outbreaks, and the flaw has repeatedly been bundled into botnets and ransomware tooling since. Anyone running unpatched Windows Vista SP2 through Windows 10 1607 / Windows Server 2016 with SMBv1 enabled is affected, as are Siemens medical and laboratory devices (ACUSON ultrasound, syngo SC2000, Tissue Preparation System, VERSANT kPCR systems) whose firmware depends on SMBv1. Exploitation is actively ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with known ransomware use, carries a 99.2% EPSS exploitation probability (100th percentile), and multiple public exploits and PoCs are available.

What to do: Apply the Microsoft MS17-010 (March 2017) security updates on every listed Windows version and the corresponding Siemens firmware updates for ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR devices, per CISA's required action to apply vendor updates. Where patching is not yet possible, disable SMBv1 or block inbound TCP 445 (and UDP 137/138) at network boundaries and isolate legacy/medical systems from the internet. Sweep exposed and legacy hosts for compromise indicators, including DOUBLEPULSAR implants delivered over SMB, as public tooling for detecting and neutralizing this implant is available.

Affected
microsoft Windows SMBv1 server (Server Message Block)Windows Vista SP2; Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012; Windows Server 2012 R2; Windows RT 8.1;
siemens ACUSON P300 firmware
siemens ACUSON P500 firmware
siemens ACUSON SC2000 firmware
siemens ACUSON X700 firmware
siemens syngo SC2000 firmware
siemens Tissue Preparation System firmware
siemens VERSANT kPCR Molecular System firmware
siemens VERSANT kPCR Sample Prep firmware
Estimated exposure
massorder of hundreds of thousands of internet-exposed SMB endpoints, and millions of unpatched Windows systems when internal enterprise and medical-device… — SMBv1 was enabled by default on every listed Windows release and internet-wide scans of TCP 445 have repeatedly shown hundreds of thousands of exposed SMB servers, so unpatched internet-facing hosts plus legacy internal fleets and embedded…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CISA Known Exploited Vulnerability
Affected
Microsoft SMBv1
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoftsiemens
Products
server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news