← Vulnerability feed

Vulnerability record · CVE-2017-0148 · published 17 March 2017

CVE-2017-0148: Microsoft Windows SMBv1 Server Remote Code Execution

Microsoft · Server Message Block

The SMBv1 server in multiple Microsoft Windows versions fails to properly validate crafted packets, allowing remote code execution. This is a distinct flaw from the other SMBv1 issues patched in the same cycle (CVE-2017-0143 through CVE-2017-0146). It matters because SMBv1 is still present on legacy Windows and some Siemens medical and lab systems, and the flaw is remotely reachable without authentication.

8.1 CVSS 3.1 High CISA KEV since 6 Apr 2022 Known ransomware use EPSS 99% · top 0.1% CWE-20 · Improper input validation
8.1CVSS 3.1 base score, v2 9.3
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
21References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has an EPSS near 1.0, is remotely exploitable without authentication, and affects both Windows and Siemens systems.

What it is

The SMBv1 server in multiple Microsoft Windows versions fails to properly validate crafted packets, allowing remote code execution. This is a distinct flaw from the other SMBv1 issues patched in the same cycle (CVE-2017-0143 through CVE-2017-0146). It matters because SMBv1 is still present on legacy Windows and some Siemens medical and lab systems, and the flaw is remotely reachable without authentication.

Impact

A remote attacker can execute arbitrary code with the privileges of the SMB service, typically SYSTEM, leading to full host compromise. CISA lists known ransomware campaign use, so an exploited host can be used for lateral movement and encryption.

Attack surface

Reached over the network via crafted SMBv1 packets to TCP port 445 (or 139). The CVSS vector shows no privileges and no user interaction required, so any host exposing SMBv1 is reachable by an unauthenticated attacker.

Exploitation

CISA KEV lists it as actively exploited with known ransomware use, and EPSS is 0.99373 (99.9th percentile). Multiple public exploit references exist, including DoublePulsar payload execution material.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0148 on all affected Windows versions.
  • Apply the Siemens product advisories (SSA-701903, SSA-966341) for affected medical and lab systems.
  • Disable SMBv1 on all hosts and block inbound TCP 445/139 at network boundaries where SMB is not required.
  • Isolate or segment legacy systems that cannot be patched or cannot drop SMBv1.

Detection

  • Monitor for SMBv1 negotiation and crafted packet patterns on TCP 445/139, especially from unexpected internal hosts.
  • Alert on DoublePulsar-related SMB traffic and known exploit signatures from the referenced Packet Storm and Exploit-DB material.
  • Audit hosts and network devices for SMBv1 enabled and for the affected Windows and Siemens firmware versions.
  • Watch for post-exploitation behavior such as new service creation, SMB session anomalies, and ransomware file encryption activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-0148 to the Known Exploited Vulnerabilities catalog on 6 April 2022 as "Microsoft SMBv1 Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 27 April 2022.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/96706 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037991 Broken LinkThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party AdvisoryUS Government Resource
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148 PatchVendor Advisory
https://www.exploit-db.com/exploits/41891/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41987/ ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/96706 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037991 Broken LinkThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party AdvisoryUS Government Resource
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148 PatchVendor Advisory
https://www.exploit-db.com/exploits/41891/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41987/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0148 US Government Resource

Track CVE-2017-0148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-0144Microsoft Windows SMBv1 server remote code executionThe SMBv1 server in multiple Microsoft Windows versions mishandles crafted packets, allowing remote code execution. The flaw is remotely reachable ov…KEVEPSS 99%analysed8.8CVE-2017-0145Microsoft Windows SMBv1 Server Remote Code ExecutionThe SMBv1 server in multiple Microsoft Windows versions mishandles crafted packets, allowing remote code execution. It is one of the SMBv1 flaws expl…KEVEPSS 90%analysed8.8CVE-2017-0146Microsoft Windows SMBv1 remote code execution flawThe SMBv1 server in multiple Microsoft Windows versions mishandles crafted packets, allowing remote code execution. It is one of the SMB flaws exploi…KEVEPSS 90%analysed8.8CVE-2017-0143Microsoft Windows SMBv1 Server Remote Code ExecutionThe SMBv1 server in multiple Microsoft Windows versions fails to properly handle crafted packets, allowing remote code execution. This is one of the …KEVEPSS 93%analysed7.5CVE-2017-0147Microsoft Windows SMBv1 Server Information Disclosure via Crafted PacketsThe SMBv1 server in multiple Microsoft Windows versions fails to properly handle crafted packets, allowing remote attackers to read sensitive data fr…KEVEPSS 100%analysed9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2017-0148), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.