CVE-2017-0146 is a critical remote code execution vulnerability affecting the SMBv1 server in various Microsoft Windows operating systems, including Windows Vista, 7, 8.1, 10, and Server versions. This flaw allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted packets. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited, notably by the WannaCry ransomware campaign, and has extensive exploit code available in frameworks like Metasploit, indicating widespread community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:* | ||
13.02CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:* | ||
13.03CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:* | ||
13.20CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:* | ||
13.21CPE matchmatch criteria | cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.