Microsoft SMBv1 Remote Code Execution Vulnerability
High CVSS 8.8 Listed in CISA KEV
Summary
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:SMBv1
- :
- :
- :
- :
- :
- :
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2017-0145 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html Exploit
- http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html Exploit
- http://www.securityfocus.com/bid/96705 Broken Link
- http://www.securitytracker.com/id/1037991 Broken Link
- https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0145 Patch
- https://www.exploit-db.com/exploits/41891/ Exploit
- https://www.exploit-db.com/exploits/41987/ Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0145 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD