CVE-2017-0148
KEV ransomware PoC ×4massRemote Code Execution in Microsoft Windows SMBv1 Server (MS17-010)
CISA: Microsoft SMBv1 Server Remote Code Execution Vulnerability
CVE-2017-0148 is a remote code execution flaw in the SMBv1 server implementation of Microsoft Windows, where improperly handled crafted SMB packets sent to an affected machine allow an attacker to execute arbitrary code without authentication. It is one of the MS17-010 'EternalBlue-family' SMBv1 bugs (distinct from but patched alongside CVE-2017-0143 through CVE-2017-0146) and is triggered by sending maliciously crafted packets to the SMBv1 service, typically reachable over the network on port 445. Successful exploitation gives an attacker the ability to run arbitrary code on the target host, enabling full system compromise, lateral movement, and, as recorded in CISA's Known Exploited Vulnerabilities catalog, ransomware deployment. All unpatched Windows releases from Windows Vista SP2 and Server 2008 through Windows 10 1607 and Server 2016 are affected by default, and Siemens also disclosed that its Acuson ultrasound systems, syngo SC2000, Tissue Preparation System, and Versant kPCR molecular diagnostics products embed the affected Microsoft SMB implementation. Exploitation is confirmed in the wild: the issue is in CISA KEV (added 2022-04-06, ransomware use known), EPSS puts 30-day exploitation probability at 99.4%, and multiple public PoC/exploit references exist, including DoublePulsar payload-execution tooling and Exploit-DB entries.
What to do: Apply the Microsoft MS17-010 (March 2017) security updates, or later cumulative updates, on all affected Windows Vista SP2 through Server 2016 systems; out-of-support platforms require the special Microsoft patches released for them. Disable SMBv1 where no longer needed and block inbound SMB (TCP 445) at the network perimeter except where required. Audit for unpatched internet-facing Windows hosts and for Siemens Acuson/syngo/Tissue Preparation System/Versant kPCR devices, applying Siemens firmware and configuration updates issued in response to Microsoft's MS17-010 advisories.
| microsoft Windows SMBv1 server (Server Message Block) | SMBv1 server as shipped in the affected Windows releases below; fixed by MS17-010 (March 2017) |
| microsoft Windows Vista | SP2 |
| microsoft Windows Server 2008 | SP2 (32/64-bit); Server 2008 R2 SP1 (Itanium/64-bit) |
| microsoft Windows 7 | SP1 (32/64-bit) |
| microsoft Windows 8.1 | all supported editions (32/64-bit) |
| microsoft Windows RT 8.1 | all editions |
| microsoft Windows Server 2012 | Gold and R2 |
| microsoft Windows 10 | Gold (1507), 1511, and 1607 (including 1607 for x64/Itanium-based systems) |
| microsoft Windows Server 2016 | Gold |
| siemens Acuson P300 ultrasound firmware | — |
| siemens Acuson P500 ultrasound firmware | — |
| siemens Acuson SC2000 ultrasound firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
- Affected
- Microsoft SMBv1 server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoftsiemens
- Products
- server message block, acuson p300 firmware, acuson p500 firmware, acuson sc2000 firmware, acuson x700 firmware, syngo sc2000 firmware, tissue preparation system firmware, versant kpcr molecular system firmware, versant kpcr sample prep firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H