LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0147: Microsoft Windows SMBv1 Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0147 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

CVE-2017-0147 is an information-disclosure vulnerability in the Microsoft SMBv1 server that lets a remote attacker obtain sensitive data from process memory by sending a crafted packet. It matters because SMBv1 is often reachable on Windows hosts used for file and printer sharing, and successful abuse can leak memory contents that aid further compromise. Public reporting links this issue to ransomware activity, so organizations still running SMBv1 should treat it as a priority.

Confirm every version, patch, and configuration detail against the official Microsoft advisory before acting; the guidance below stays within the published facts and general practices for this weakness class.

How it works

The flaw is classified as CWE-200 (exposure of sensitive information). In the SMBv1 server implementation, improper handling of a specially crafted network packet can cause the service to return data from process memory that should not be disclosed to an unauthenticated or unauthorized remote party. An attacker who can reach the SMBv1 listener crafts and sends such a packet; the server responds with memory contents that may include credentials, cryptographic material, or other in-process secrets. No further exploit mechanics are detailed in the available facts; defenders should treat any unexpected SMBv1 traffic that elicits unusual responses as potentially malicious and verify behavior against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft SMBv1 server components typically run on Windows workstations, member servers, and domain controllers that still have the legacy SMB 1.0/CIFS File Sharing Support feature enabled. Inventory steps include:

Telemetry signs of attempted exploitation are limited in public detail; look for anomalous SMBv1 session establishments, unexpected packet sizes or malformed requests reaching the server, and any subsequent unusual process-memory access or lateral-movement activity. Correlate with authentication logs and endpoint detection alerts. Exact indicators must be confirmed against the vendor advisory and your own threat-intelligence sources.

How to remediate

Apply the security updates Microsoft released for this vulnerability, following the vendor’s instructions exactly. After patching:

CISA’s required action is simply to apply updates per vendor instructions; complete that step first, then harden.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

These measures lower risk but do not replace the official update.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been used in ransomware campaigns, so any confirmed or suspected compromise should trigger incident-response procedures: isolate affected hosts, preserve memory and disk evidence, rotate credentials that may have resided in process memory, and hunt for follow-on activity. As a quick external check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related credentials have already appeared in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SMBv1 server
WeaknessCWE-200
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities