LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0146: Microsoft Windows SMB Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0146 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

CVE-2017-0146 is a remote code execution vulnerability in the SMBv1 server component of Microsoft Windows. Improper handling of input allows a remote attacker to execute code on a vulnerable system. It matters because successful exploitation can give an attacker control of the host, and this vulnerability has been used in ransomware campaigns. Confirm all product and version details against the vendor advisory.

Organizations still running SMBv1-facing Windows systems should treat this as a high-priority exposure until patched or otherwise mitigated. The CISA-required action is to apply updates per vendor instructions.

How it works

The underlying weakness is CWE-20 (Improper Input Validation). The SMBv1 server in Microsoft Windows does not adequately validate certain input from network clients. An attacker who can reach the SMBv1 service can send crafted requests that cause the server to execute attacker-controlled code in the context of the vulnerable process.

Abuse typically requires network access to the SMB service (commonly TCP 445). No further exploit mechanics are detailed here; treat any public proof-of-concept or weaponized tooling as untrusted until validated in a controlled lab, and always confirm behavior and preconditions against the vendor advisory. Because the flaw enables remote code execution, it can be chained into lateral movement, credential theft, or ransomware deployment once a foothold exists.

Am I affected? How to find it in your systems

This vulnerability affects Microsoft Windows systems that expose the SMBv1 server. SMBv1 has historically been enabled by default on many Windows releases and is commonly found on file servers, domain controllers, workstations, and legacy appliances that still speak SMBv1.

How to remediate

Patch first. Apply the security updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA. After patching, verify that the update is installed and that the SMBv1 server is either removed or no longer reachable from untrusted networks.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited remote code execution vulnerabilities, including those known to be used by ransomware, frequently lead to data theft or encryption. If you have evidence of exploitation or ransomware activity on affected Windows hosts, follow your incident-response plan: isolate systems, preserve forensic evidence, reset credentials, and assess what data may have been accessed or exfiltrated. You can run a free exposure scan of your email addresses to check whether they appear in known breach datasets and then monitor for follow-on account takeover attempts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-20
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities