Vulnerability record · CVE-2017-0148 · published 17 March 2017
CVE-2017-0148: Microsoft Windows SMBv1 Server Remote Code Execution
Microsoft · Server Message Block
The SMBv1 server in multiple Microsoft Windows versions fails to properly validate crafted packets, allowing remote code execution. This is a distinct flaw from the other SMBv1 issues patched in the same cycle (CVE-2017-0143 through CVE-2017-0146). It matters because SMBv1 is still present on legacy Windows and some Siemens medical and lab systems, and the flaw is remotely reachable without authentication.
Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has an EPSS near 1.0, is remotely exploitable without authentication, and affects both Windows and Siemens systems.
What it is
The SMBv1 server in multiple Microsoft Windows versions fails to properly validate crafted packets, allowing remote code execution. This is a distinct flaw from the other SMBv1 issues patched in the same cycle (CVE-2017-0143 through CVE-2017-0146). It matters because SMBv1 is still present on legacy Windows and some Siemens medical and lab systems, and the flaw is remotely reachable without authentication.
Impact
A remote attacker can execute arbitrary code with the privileges of the SMB service, typically SYSTEM, leading to full host compromise. CISA lists known ransomware campaign use, so an exploited host can be used for lateral movement and encryption.
Attack surface
Reached over the network via crafted SMBv1 packets to TCP port 445 (or 139). The CVSS vector shows no privileges and no user interaction required, so any host exposing SMBv1 is reachable by an unauthenticated attacker.
Exploitation
CISA KEV lists it as actively exploited with known ransomware use, and EPSS is 0.99373 (99.9th percentile). Multiple public exploit references exist, including DoublePulsar payload execution material.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0148 on all affected Windows versions.
- Apply the Siemens product advisories (SSA-701903, SSA-966341) for affected medical and lab systems.
- Disable SMBv1 on all hosts and block inbound TCP 445/139 at network boundaries where SMB is not required.
- Isolate or segment legacy systems that cannot be patched or cannot drop SMBv1.
Detection
- Monitor for SMBv1 negotiation and crafted packet patterns on TCP 445/139, especially from unexpected internal hosts.
- Alert on DoublePulsar-related SMB traffic and known exploit signatures from the referenced Packet Storm and Exploit-DB material.
- Audit hosts and network devices for SMBv1 enabled and for the affected Windows and Siemens firmware versions.
- Watch for post-exploitation behavior such as new service creation, SMB session anomalies, and ransomware file encryption activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0148 to the Known Exploited Vulnerabilities catalog on 6 April 2022 as "Microsoft SMBv1 Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 27 April 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0148 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0148), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.