CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607...
Description
This CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov
In plain language
AI Act nowCVE-2017-0146 is a serious flaw in the SMBv1 file-sharing feature of older Windows systems; if your SMBv1 server is reachable from the network, a typical small business should treat it as an urgent fix—attackers have used it in ransomware campaigns.
CVE-2017-0146 is a remotely triggerable SMBv1 server weakness in Microsoft Windows (various older Windows versions), where attackers can send crafted SMBv1 traffic to compromise the machine; it has been confirmed in real-world ransomware activity (CISA KEV).
What to do now
- Check which Windows machines you run and whether they have SMBv1 enabled (SMBv1 server reachable on TCP 445).
- Identify machines exposed to the network (especially anything reachable from the internet, untrusted offices, or guest networks).
- For any affected machine, disable SMBv1 and apply Microsoft security updates using the vendor instructions for CVE-2017-0146.
- Confirm after changes that SMBv1 is no longer enabled and that the security update(s) for CVE-2017-0146 have been installed on the affected systems.
- Re-check exposure after patching by testing whether SMBv1 negotiation is possible and reviewing logs for SMBv1-related traffic spikes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-0146 and every CVE in our database. Create a free account — no credit card required.
Create Free Account