CVE-2017-0146
KEV ransomware PoC ×5massRemote Code Execution in Microsoft Windows SMBv1 Server (MS17-010)
CISA: Microsoft Windows SMB Remote Code Execution Vulnerability
CVE-2017-0146 is a remote code execution flaw in the Microsoft Windows SMBv1 server that is triggered when the vulnerable service processes specially crafted SMB packets, one of a family of related SMBv1 bugs (CVE-2017-0143/0144/0145/0148) publicly leaked by the Shadow Brokers and fixed by Microsoft in the MS17-010 April 2017 bulletin. An attacker with limited privileges who can reach the SMB service over the network can execute arbitrary code in kernel context, gaining a foothold for lateral movement and follow-on payloads such as ransomware or cryptocurrency miners. Affected systems span Windows Vista SP2 through Windows Server 2016, as well as Siemens medical and laboratory products (Acuson ultrasound, syngo, Versant kPCR systems) that run on affected Windows platforms. Public exploit code exists, including Metasploit ports of the NSA EternalRomance/EternalSynergy/EternalChampion exploits, and the vulnerability is in CISA's Known Exploited Vulnerabilities catalog with documented ransomware use. Exploitation probability is extremely high (EPSS 89.9%, top percentile), so unpatched systems remain at immediate risk.
What to do: Apply Microsoft's MS17-010 (April 2017) security updates on all affected Windows versions, and apply Siemens' published firmware/security updates for Acuson, syngo, Tissue Preparation System, and Versant kPCR products. As an interim mitigation, disable SMBv1 where possible and restrict inbound access to TCP/445; check hosts for signs of compromise such as the DOUBLEPULSAR implant. This CVE is in CISA's KEV catalog with known ransomware use, so prioritize internet-facing and clinical/network-segmented but unpatched systems immediately.
| Microsoft Windows SMBv1 server | Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1 |
| Siemens Acuson P300 firmware | — |
| Siemens Acuson P500 firmware | — |
| Siemens Acuson SC2000 firmware | — |
| Siemens Acuson X700 firmware | — |
| Siemens syngo SC2000 firmware | — |
| Siemens Tissue Preparation System firmware | — |
| Siemens Versant kPCR Molecular System firmware | — |
| Siemens Versant kPCR Sample Prep firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoftsiemens
- Products
- server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H