ZeroHour

CVE-2017-0146

KEV ransomware PoC ×5mass

Remote Code Execution in Microsoft Windows SMBv1 Server (MS17-010)

CISA: Microsoft Windows SMB Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2017-0146 is a remote code execution flaw in the Microsoft Windows SMBv1 server that is triggered when the vulnerable service processes specially crafted SMB packets, one of a family of related SMBv1 bugs (CVE-2017-0143/0144/0145/0148) publicly leaked by the Shadow Brokers and fixed by Microsoft in the MS17-010 April 2017 bulletin. An attacker with limited privileges who can reach the SMB service over the network can execute arbitrary code in kernel context, gaining a foothold for lateral movement and follow-on payloads such as ransomware or cryptocurrency miners. Affected systems span Windows Vista SP2 through Windows Server 2016, as well as Siemens medical and laboratory products (Acuson ultrasound, syngo, Versant kPCR systems) that run on affected Windows platforms. Public exploit code exists, including Metasploit ports of the NSA EternalRomance/EternalSynergy/EternalChampion exploits, and the vulnerability is in CISA's Known Exploited Vulnerabilities catalog with documented ransomware use. Exploitation probability is extremely high (EPSS 89.9%, top percentile), so unpatched systems remain at immediate risk.

What to do: Apply Microsoft's MS17-010 (April 2017) security updates on all affected Windows versions, and apply Siemens' published firmware/security updates for Acuson, syngo, Tissue Preparation System, and Versant kPCR products. As an interim mitigation, disable SMBv1 where possible and restrict inbound access to TCP/445; check hosts for signs of compromise such as the DOUBLEPULSAR implant. This CVE is in CISA's KEV catalog with known ransomware use, so prioritize internet-facing and clinical/network-segmented but unpatched systems immediately.

Affected
Microsoft Windows SMBv1 serverWindows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1
Siemens Acuson P300 firmware
Siemens Acuson P500 firmware
Siemens Acuson SC2000 firmware
Siemens Acuson X700 firmware
Siemens syngo SC2000 firmware
Siemens Tissue Preparation System firmware
Siemens Versant kPCR Molecular System firmware
Siemens Versant kPCR Sample Prep firmware
Estimated exposure
masshundreds of millions of Windows installations worldwide; on the order of hundreds of thousands to millions of SMB endpoints exposed to scanning networks, plus… — The affected Windows versions (Vista SP2 through Server 2016) constituted the dominant share of the global Windows install base when MS17-010 shipped, and public internet scans of port 445/SMBv1 during the 2017 EternalBlue wave found…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoftsiemens
Products
server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news