CVE-2017-0145
KEV ransomware PoC ×4massRemote Code Execution in Microsoft SMBv1 Affecting Windows and Siemens Devices
CISA: Microsoft SMBv1 Remote Code Execution Vulnerability
CVE-2017-0145 is a remote code execution flaw in the SMBv1 server implementation shipped with a wide range of Microsoft Windows releases, allowing remote attackers to run arbitrary code by sending specially crafted SMBv1 packets to the SMB service (typically over TCP port 445). A successful attack gives the attacker code execution on the target host, which has been widely leveraged to install backdoors (e.g., DoublePulsar per the public exploit references) and to propagate ransomware such as Bad Rabbit, whose use of the leaked NSA 'EternalRomance' SMB exploit is reflected in current threat reporting. Affected systems include Windows Vista SP2, Windows Server 2008 SP2/R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows RT 8.1, Windows 10 Gold/1511/1607, and Windows Server 2016, plus Siemens medical and laboratory systems (ACUSON ultrasound and VERSANT kPCR product lines) that embed SMBv1 in their firmware. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) with known ransomware use, and its 89.8% EPSS score (99th+ percentile) indicates a very high likelihood of exploitation within 30 days. This flaw is distinct from the sibling SMBv1 issues tracked as CVE-2017-0143, 0144, 0146, and 0148, so defenses should address the whole SMBv1 family.
What to do: Apply the vendor patches per CISA's required action — Microsoft addressed this SMBv1 flaw family in the MS17-010 security update, and Siemens has issued firmware updates for the listed ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR products. As interim mitigation, disable SMBv1 where possible and restrict or block inbound TCP 445 from untrusted networks, then verify no active compromise (e.g., DoublePulsar implants) on systems that were exposed. Prioritize patching internet-facing Windows hosts and clinical/lab devices, since the flaw is under active ransomware exploitation.
| Microsoft SMBv1 server (Windows) | Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, |
| Siemens ACUSON P300 firmware | — |
| Siemens ACUSON P500 firmware | — |
| Siemens ACUSON SC2000 firmware | — |
| Siemens ACUSON X700 firmware | — |
| Siemens syngo SC2000 firmware | — |
| Siemens Tissue Preparation System firmware | — |
| Siemens VERSANT kPCR Molecular System firmware | — |
| Siemens VERSANT kPCR Sample Prep firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
- Affected
- Microsoft SMBv1
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoftsiemens
- Products
- server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H