LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0148: Microsoft SMBv1 Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 6, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 27, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0148 to its Known Exploited Vulnerabilities catalog on Apr 6, 2022, with a federal patch deadline of Apr 27, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

CVE-2017-0148 is a remote code execution vulnerability in the Microsoft SMBv1 server. It allows remote attackers to run arbitrary code by sending crafted packets to an affected system. This matters because successful exploitation can give an attacker full control of the host, and the vulnerability is known to have been used by ransomware. Organizations still running SMBv1 should treat it as a high-priority exposure and confirm details against the vendor advisory.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). The SMBv1 server fails to properly validate certain incoming network packets. An attacker who can reach the service over the network can send specially crafted SMB packets that cause the server to execute attacker-controlled code in the context of the vulnerable process. No authentication is described as required in the public summary; reachability of the SMBv1 service is the primary precondition. Exact packet structure and exploitation mechanics are not detailed here and must be confirmed against the vendor advisory. Because the flaw enables remote code execution, it has been leveraged in ransomware campaigns.

Am I affected? How to find it in your systems

The vulnerability affects the Microsoft SMBv1 server component. SMBv1 commonly runs on Windows servers and workstations that still have the legacy file-and-printer sharing protocol enabled, including domain controllers, file servers, and older endpoints. To inventory exposure:

Any host still offering SMBv1 should be treated as potentially vulnerable until patched or the protocol is disabled and validated.

How to remediate

The required action is to apply updates per vendor instructions. Obtain and deploy the security update that addresses CVE-2017-0148 from Microsoft, following your standard change-control and testing process. After patching:

Confirm the precise package names, reboot requirements, and superseding updates directly from the vendor advisory.

If you can't patch immediately

If immediate patching is not possible, apply compensating controls to reduce risk until the update can be installed:

These measures do not replace the vendor update; they only buy time while you schedule patching.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities, especially those known to be used by ransomware, frequently lead to data theft, encryption, or further lateral movement. If you have evidence of exploitation or believe sensitive data may have left your environment, follow your incident-response plan: isolate affected hosts, preserve forensic evidence, and assess what information was accessible. You can also run a free exposure scan of your email addresses to check whether they appear in known breach datasets and take additional account-protection steps accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SMBv1 server
WeaknessCWE-20
Added to CISA KEVApr 6, 2022
Federal patch deadlineApr 27, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities