LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0143: Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0143 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

CVE-2017-0143 is a remote code execution vulnerability in Microsoft Windows Server Message Block version 1.0 (SMBv1). An attacker who can reach a vulnerable SMBv1 service may be able to run code on the target system without valid credentials. It matters because SMBv1 has historically been exposed on internal networks and, in some environments, on perimeter systems; the flaw has been used in ransomware campaigns, so unpatched hosts remain a high-priority risk.

Public detail on exact mechanics is limited beyond the CWE and the CISA description. Confirm affected products, builds, and fixes directly against the Microsoft advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In broad terms for this class, the SMBv1 implementation does not adequately validate certain protocol data before processing it. An attacker who can send crafted SMBv1 traffic to a listening service may trigger memory corruption or similar unsafe handling that leads to arbitrary code execution in the context of the SMB service (typically SYSTEM on Windows).

Abuse generally requires network reachability to the SMBv1 endpoint. No further exploit specifics are provided in the given record; treat any public proof-of-concept claims cautiously and validate behavior only in controlled lab conditions against vendor guidance. Because the vulnerability enables remote code execution and has known ransomware use, successful exploitation can lead to full host compromise, lateral movement, and encryption or theft of data.

Am I affected? How to find it in your systems

SMBv1 is a legacy file- and printer-sharing protocol built into Microsoft Windows client and server editions. It may still be enabled by default on older images, or left on for compatibility with legacy devices, scanners, or NAS gear.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2017-0143 exactly as directed in the vendor advisory and per the CISA required action: “Apply updates per vendor instructions.” Use your standard test-and-deploy process, prioritizing internet-facing or high-value systems and domain controllers.

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

If your data may have been exposed

Actively exploited remote code execution flaws, especially those with known ransomware use, frequently precede data theft or encryption. If you have evidence of exploitation or cannot rule it out, follow your incident-response plan: isolate affected hosts, preserve volatile evidence, reset credentials, and assess whether sensitive data left the environment. As a simple additional check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior public dumps, then force password changes and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities