CVE Tools

CVE-2017-0146

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607...

Published: Mar 17, 2017Updated: Apr 22, 2026 Sources: CVE List NVD BDU csafNVD-CWE-noinfo

Description

This CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov

In plain language

AI Act now

CVE-2017-0146 is a serious flaw in the SMBv1 file-sharing feature of older Windows systems; if your SMBv1 server is reachable from the network, a typical small business should treat it as an urgent fix—attackers have used it in ransomware campaigns.

Executive summary

CVE-2017-0146 is a remotely triggerable SMBv1 server weakness in Microsoft Windows (various older Windows versions), where attackers can send crafted SMBv1 traffic to compromise the machine; it has been confirmed in real-world ransomware activity (CISA KEV).

If affected, business impact
Ransomware infection through file sharingFull server compromiseBusiness disruption from shutdownsLoss of access to shared files

What to do now

  1. Check which Windows machines you run and whether they have SMBv1 enabled (SMBv1 server reachable on TCP 445).
  2. Identify machines exposed to the network (especially anything reachable from the internet, untrusted offices, or guest networks).
  3. For any affected machine, disable SMBv1 and apply Microsoft security updates using the vendor instructions for CVE-2017-0146.
  4. Confirm after changes that SMBv1 is no longer enabled and that the security update(s) for CVE-2017-0146 have been installed on the affected systems.
  5. Re-check exposure after patching by testing whether SMBv1 negotiation is possible and reviewing logs for SMBv1-related traffic spikes.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 25, 2022
Remediation due:Apr 15, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

5 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 69 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-0146 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows