ZeroHour

CVE-2017-0148

KEV ransomware PoC ×4mass

Remote Code Execution in Microsoft Windows SMBv1 Server (MS17-010)

CISA: Microsoft SMBv1 Server Remote Code Execution Vulnerability

CVSS 3.1
8.1 high
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2017-0148 is a remote code execution flaw in the SMBv1 server implementation of Microsoft Windows, where improperly handled crafted SMB packets sent to an affected machine allow an attacker to execute arbitrary code without authentication. It is one of the MS17-010 'EternalBlue-family' SMBv1 bugs (distinct from but patched alongside CVE-2017-0143 through CVE-2017-0146) and is triggered by sending maliciously crafted packets to the SMBv1 service, typically reachable over the network on port 445. Successful exploitation gives an attacker the ability to run arbitrary code on the target host, enabling full system compromise, lateral movement, and, as recorded in CISA's Known Exploited Vulnerabilities catalog, ransomware deployment. All unpatched Windows releases from Windows Vista SP2 and Server 2008 through Windows 10 1607 and Server 2016 are affected by default, and Siemens also disclosed that its Acuson ultrasound systems, syngo SC2000, Tissue Preparation System, and Versant kPCR molecular diagnostics products embed the affected Microsoft SMB implementation. Exploitation is confirmed in the wild: the issue is in CISA KEV (added 2022-04-06, ransomware use known), EPSS puts 30-day exploitation probability at 99.4%, and multiple public PoC/exploit references exist, including DoublePulsar payload-execution tooling and Exploit-DB entries.

What to do: Apply the Microsoft MS17-010 (March 2017) security updates, or later cumulative updates, on all affected Windows Vista SP2 through Server 2016 systems; out-of-support platforms require the special Microsoft patches released for them. Disable SMBv1 where no longer needed and block inbound SMB (TCP 445) at the network perimeter except where required. Audit for unpatched internet-facing Windows hosts and for Siemens Acuson/syngo/Tissue Preparation System/Versant kPCR devices, applying Siemens firmware and configuration updates issued in response to Microsoft's MS17-010 advisories.

Affected
microsoft Windows SMBv1 server (Server Message Block)SMBv1 server as shipped in the affected Windows releases below; fixed by MS17-010 (March 2017)
microsoft Windows VistaSP2
microsoft Windows Server 2008SP2 (32/64-bit); Server 2008 R2 SP1 (Itanium/64-bit)
microsoft Windows 7SP1 (32/64-bit)
microsoft Windows 8.1all supported editions (32/64-bit)
microsoft Windows RT 8.1all editions
microsoft Windows Server 2012Gold and R2
microsoft Windows 10Gold (1507), 1511, and 1607 (including 1607 for x64/Itanium-based systems)
microsoft Windows Server 2016Gold
siemens Acuson P300 ultrasound firmware
siemens Acuson P500 ultrasound firmware
siemens Acuson SC2000 ultrasound firmware
Estimated exposure
massmass-scale: on the order of millions of unpatched Windows systems, with hundreds of thousands having SMB (port 445) exposed — SMBv1 was enabled by default on every listed Windows release through Server 2016, and public internet scans plus the WannaCry outbreak (200,000+ machines infected across ~150 countries within days) demonstrated hundreds of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

CISA Known Exploited Vulnerability
Affected
Microsoft SMBv1 server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoftsiemens
Products
server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news