CVE-2017-0145 is a critical remote code execution vulnerability affecting the SMBv1 server in various Microsoft Windows operating systems, including Vista, Windows 7, 8.1, 10, and several Windows Server versions. With a CVSS score of 8.8 (HIGH), this flaw allows unauthenticated remote attackers to execute arbitrary code with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, notably by ransomware campaigns, and has readily available exploit modules in Metasploit, including the infamous EternalBlue. The vulnerability has garnered significant community and media attention, underscoring its widespread impact and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* | ||
13.02CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* | ||
13.03CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* | ||
13.20CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* | ||
13.21CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.