Vulnerability record · CVE-2017-0147 · published 17 March 2017
CVE-2017-0147: Microsoft Windows SMBv1 Server Information Disclosure via Crafted Packets
Microsoft · Windows 10 1507
The SMBv1 server in multiple Microsoft Windows versions fails to properly handle crafted packets, allowing remote attackers to read sensitive data from process memory. This is the information disclosure component of the SMBv1 flaws exploited by EternalBlue/DoublePulsar, and it matters because it leaks memory contents that can aid further attacks and because the affected protocol is still present on many unpatched and legacy systems.
Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use and has an EPSS probability near 1.0, and the affected SMBv1 service is widely deployed and remotely reachable without authentication.
What it is
The SMBv1 server in multiple Microsoft Windows versions fails to properly handle crafted packets, allowing remote attackers to read sensitive data from process memory. This is the information disclosure component of the SMBv1 flaws exploited by EternalBlue/DoublePulsar, and it matters because it leaks memory contents that can aid further attacks and because the affected protocol is still present on many unpatched and legacy systems.
Impact
An unauthenticated remote attacker can obtain sensitive information from process memory, potentially exposing credentials, cryptographic material, or memory layout details useful for follow-on exploitation. The flaw itself does not grant code execution or data modification.
Attack surface
Reachable over the network via the SMBv1 service, typically TCP port 445, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any host exposing SMBv1 is in scope.
Exploitation
CVE-2017-0147 is listed in CISA KEV with known ransomware campaign use, and EPSS shows a 30-day probability of 0.99693 (99.95th percentile); multiple public exploit references exist, including DoublePulsar payload material.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for all affected Windows versions.
- Disable SMBv1 on all hosts and servers where it is not strictly required.
- Block inbound SMB (TCP 445) from untrusted networks at the perimeter and between network segments.
- For Siemens and other affected third-party products, apply the vendor advisories (SSA-701903, SSA-966341, ICSMA-18-058-02).
- Retire or isolate unsupported legacy systems that cannot be patched.
Detection
- Monitor for SMBv1 negotiation and anomalous SMB traffic on TCP 445, especially from unexpected external or cross-segment sources.
- Alert on known exploit tooling signatures and DoublePulsar-related artifacts referenced in public exploit write-ups.
- Audit hosts for SMBv1 enabled status and track remediation of unpatched systems.
- Correlate SMB connection events with subsequent suspicious process or service activity on the target host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0147 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Microsoft Windows SMBv1 Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0147 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0147), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.