Vulnerability record · CVE-2017-0145 · published 17 March 2017
CVE-2017-0145: Microsoft Windows SMBv1 Server Remote Code Execution
Microsoft · Server Message Block
The SMBv1 server in multiple Microsoft Windows versions mishandles crafted packets, allowing remote code execution. It is one of the SMBv1 flaws exploited by the EternalBlue/DoublePulsar toolset and is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use. The record does not specify the exact memory-safety root cause (CWE is listed as insufficient information).
Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, public exploits exist, and it enables remote code execution with full host compromise.
What it is
The SMBv1 server in multiple Microsoft Windows versions mishandles crafted packets, allowing remote code execution. It is one of the SMBv1 flaws exploited by the EternalBlue/DoublePulsar toolset and is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use. The record does not specify the exact memory-safety root cause (CWE is listed as insufficient information).
Impact
A remote attacker can execute arbitrary code on the target host, typically with SYSTEM privileges, leading to full host compromise. Because SMBv1 is widely used for file sharing, a single compromised host can be used to move laterally across a network.
Attack surface
Reachable over the network via SMB (TCP 445/139) by sending crafted packets to the SMBv1 server; the CVSS vector indicates network access with low privileges required and no user interaction. No authentication is implied by the description, though the CVSS vector lists PR:L.
Exploitation
CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is 0.8985 (99.78th percentile). Multiple references are tagged Exploit, including public DoublePulsar and Exploit-DB entries.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0145 as soon as possible.
- Disable SMBv1 on all Windows systems and, where possible, on affected Siemens and third-party products.
- Block inbound SMB (TCP 445/139) at network boundaries and segment networks to limit lateral movement.
- Monitor for and remove EternalBlue/DoublePulsar artifacts on hosts that may have been previously compromised.
- For legacy or embedded systems that cannot be patched, isolate them on restricted VLANs with strict access controls.
Detection
- Hunt for SMBv1 negotiation traffic and anomalous SMB packets on TCP 445/139 using network IDS signatures for EternalBlue/DoublePulsar.
- Monitor Windows event logs and EDR telemetry for unexpected SYSTEM-level process creation or service installation originating from SMB activity.
- Scan hosts and network devices for SMBv1 enabled and for known DoublePulsar implant indicators.
- Review firewall and NetFlow logs for internal SMB connections that deviate from normal file-sharing patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0145 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft SMBv1 Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0145 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0145), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.