CVE Tools

CVE-2017-0146

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607...

Exploited in the wild. In CISA KEV since 2022‑03‑25. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU, CSAF

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check which Windows machines you run and whether they have SMBv1 enabled (SMBv1 server reachable on TCP 445).
  2. Identify machines exposed to the network (especially anything reachable from the internet, untrusted offices, or guest networks).
  3. For any affected machine, disable SMBv1 and apply Microsoft security updates using the vendor instructions for CVE-2017-0146.
  4. Confirm after changes that SMBv1 is no longer enabled and that the security update(s) for CVE-2017-0146 have been installed on the affected systems.
  5. Re-check exposure after patching by testing whether SMBv1 negotiation is possible and reviewing logs for SMBv1-related traffic spikes.

What it is

From the CVE record

This CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov

In plain language

Written by AI from the record

CVE-2017-0146 is a serious flaw in the SMBv1 file-sharing feature of older Windows systems; if your SMBv1 server is reachable from the network, a typical small business should treat it as an urgent fix—attackers have used it in ransomware campaigns.

CVE-2017-0146 is a remotely triggerable SMBv1 server weakness in Microsoft Windows (various older Windows versions), where attackers can send crafted SMBv1 traffic to compromise the machine; it has been confirmed in real-world ransomware activity (CISA KEV).

If you're affected

  • Ransomware infection through file sharing
  • Full server compromise
  • Business disruption from shutdowns
  • Loss of access to shared files

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2022-03-25.

US federal agencies must remediate by 2022-04-15.

Known use in ransomware campaigns.

Apply updates per vendor instructions.
Public exploits

5 sources with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

90% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

A public exploit existed 47 days before the patch.

  1. OpenVAS check added
  2. EPSS band changecritical → high
  3. Patch availablerecord updated
  4. Public exploit / PoCsource: packetstorm
  5. Added to CISA KEVransomware campaign
  6. Publishedweakness classified

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Scored 8.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required LowRequires basic user-level privileges
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Windows XP, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store