CVE-2017-0144: EternalBlue
A remote code execution vulnerability in Microsoft's SMBv1 server caused by improper handling of specially crafted packets. Originally an NSA exploit tool, it was leaked by the Shadow Brokers in April 2017 and became the propagation mechanism for the WannaCry and NotPetya worms weeks later.
View the authoritative record on NVD ↗Affected software
- Windows Vista, 7, 8.1, and early Windows 10 builds
- Windows Server 2008, 2008 R2, 2012, 2012 R2, and 2016 with SMBv1 enabled
How it's exploited
Send specially crafted SMBv1 packets to an exposed port 445; a flaw in how SMBv1 handles them lets an unauthenticated remote attacker execute arbitrary code as SYSTEM, with no user interaction required.
Severity
CVE-2017-0144 carries a CVSS 3.1 base score of 8.8, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2017-0144 is categorized under CWE-20, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply the MS17-010 security update, disable SMBv1 entirely on all hosts, and block inbound SMB (port 445) at the network perimeter.
Frequently asked questions
What is CVE-2017-0144?
A remote code execution vulnerability in Microsoft's SMBv1 server caused by improper handling of specially crafted packets. Originally an NSA exploit tool, it was leaked by the Shadow Brokers in April 2017 and became the propagation mechanism for the WannaCry and NotPetya worms weeks later.
How severe is CVE-2017-0144?
CVE-2017-0144 has a CVSS 3.1 base score of 8.8 out of 10, rated High.
What software is affected by CVE-2017-0144?
CVE-2017-0144 affects Windows Vista, 7, 8.1, and early Windows 10 builds; Windows Server 2008, 2008 R2, 2012, 2012 R2, and 2016 with SMBv1 enabled.
How do you fix CVE-2017-0144?
Apply the MS17-010 security update, disable SMBv1 entirely on all hosts, and block inbound SMB (port 445) at the network perimeter.
Where is the authoritative record for CVE-2017-0144?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2017-0144 at https://nvd.nist.gov/vuln/detail/CVE-2017-0144, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest