CVE-2017-0144 is a critical remote code execution vulnerability affecting the SMBv1 server in various Microsoft Windows operating systems, including Vista, Windows 7, 8.1, 10, and several Windows Server versions. This flaw allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems by sending specially crafted packets. The vulnerability carries a high CVSS score of 8.8, indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Its EPSS score of 0.94318 and FAUCET Risk Score of 100/100 highlight its extreme exploitability and potential for widespread damage. CVE-2017-0144, famously known as "EternalBlue," is actively exploited in the wild, notably by ransomware campaigns. Publicly available exploit modules exist in Metasploit and ExploitDB, demonstrating its ease of exploitation. The vulnerability has garnered significant community discussion and media coverage, underscoring its historical and ongoing importance in cybersecurity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* | ||
13.02CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* | ||
13.03CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* | ||
13.20CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* | ||
13.21CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Bosch Recording Station (BRS)
May 27, 2020Multiple Vulnerabilities in Bosch Recording Station (BRS)
May 27, 2020Multiple Vulnerabilities in Bosch Recording Station (BRS)
May 27, 2020Multiple Vulnerabilities in Bosch Recording Station (BRS)
May 27, 2020Multiple Vulnerabilities in Bosch Recording Station (BRS)
May 27, 2020Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN
May 15, 2017Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN
May 15, 2017Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN
May 15, 2017Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN
May 15, 2017Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN
May 15, 2017Windows SMB Remote Code Execution Vulnerability
Mar 14, 2017