CVE-2017-0147

HIGH KEV RANSOMWARE

Microsoft Windows 10 1507 < 4.0e - Information Disclosure

Title source: rule

Description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

Exploits (8)

nomisec SUSPICIOUS
by RobertoLeonFR-ES · poc
https://github.com/RobertoLeonFR-ES/Exploit-Win32.CVE-2017-0147.A
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/43970
exploitdb WORKING POC
by Juan Sacco · pythonremotewindows_x86-64
https://www.exploit-db.com/exploits/41987
exploitdb SCANNER VERIFIED
by Sean Dillon · rubydoswindows
https://www.exploit-db.com/exploits/41891
metasploit SCANNER
by Sean Dillon <[email protected]>, Luke Jennings · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/smb/smb_ms17_010.rb
metasploit WORKING POC NORMAL
by Equation Group, Shadow Brokers, sleepya, Sean Dillon <[email protected]>, Dylan Davis <[email protected]>, thelightcosine, wvu, s first external module, , # External python module · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/smb/ms17_010_eternalblue.rb
metasploit WORKING POC GREAT
by Equation Group, Shadow Brokers, zerosum0x0, Luke Jennings, wvu, Jacob Robles · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/smb/smb_doublepulsar_rce.rb
exploitdb WORKING POC
rubyremotewindows
https://www.exploit-db.com/exploits/47456

Scores

CVSS v3 7.5
EPSS 0.9242
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

CISA KEV 2022-05-24
VulnCheck KEV 2017-03-14
InTheWild.io 2017-03-14
ENISA EUVD EUVD-2017-0514
Ransomware Use Confirmed

Classification

Status draft

Affected Products (27)

microsoft/windows_10_1507
microsoft/windows_10_1511
microsoft/windows_10_1607
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2012
microsoft/windows_server_2012
microsoft/windows_server_2016
microsoft/windows_vista
siemens/acuson_p300_firmware
siemens/acuson_p300_firmware
siemens/acuson_p300_firmware
... and 12 more

Timeline

Published Mar 17, 2017
KEV Added May 24, 2022
Tracked Since Feb 18, 2026