# CVE-2017-0144 — Microsoft Corporation Windows SMB

**CISA KEV** · **Ransomware**

> As of 2026-08-14, CVE-2017-0144 is a HIGH-severity vulnerability in Microsoft Corporation Windows SMB, CVSS v3.1 8.8, EPSS 99.2% (99.9th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-02-10), with a US federal remediation deadline of 2022-08-10, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2017-0144, most recently “Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition”.

**Last updated:** 2026-08-14

## What is CVE-2017-0144?

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 3476 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 8.8 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 99.2% probability of exploitation in the next 30 days, higher than 99.9% of all scored CVEs
- **CISA KEV:** Listed since 2022-02-10, federal remediation deadline 2022-08-10 — used in known ransomware campaigns
- **Threadlinqs priority:** 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- **Published:** 2017-03-17, last modified 2026-08-14

## Is CVE-2017-0144 being exploited?

CISA added CVE-2017-0144 to the Known Exploited Vulnerabilities catalog on 2022-02-10, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2022-08-10 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. Weaponised exploit code for CVE-2017-0144 is publicly available. 11 public proof-of-concept repositories are tracked for this identifier. It currently carries a trending score of 43 in the Threadlinqs vulnerability feed.

- [peterpt/eternal_scanner](https://github.com/peterpt/eternal_scanner) (github)
- [EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution](https://github.com/EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution) (github)
- [AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint](https://github.com/AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint) (github)
- [AtithKhawas/autoblue](https://github.com/AtithKhawas/autoblue) (github)
- [sethwhy/BlueDoor](https://github.com/sethwhy/BlueDoor) (github)
- [0xBlackash/CVE-2017-0144](https://github.com/0xBlackash/CVE-2017-0144) (github)
- [kimocoder/eternalblue](https://github.com/kimocoder/eternalblue) (github)
- [MedX267/EternalBlue-Vulnerability-Scanner](https://github.com/MedX267/EternalBlue-Vulnerability-Scanner) (github)

## Affected products and versions

- **Microsoft Corporation**: Windows SMB

## How to fix CVE-2017-0144

The record marks a vendor fix as available for CVE-2017-0144. Patch reference: [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144). Vendor advisory: [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144). Because CVE-2017-0144 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2022-08-10. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2017-0144

2 tracked threats in the Threadlinqs corpus reference CVE-2017-0144, either in the campaign’s CVE list or as an indicator on the campaign record.

- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition](https://intel.threadlinqs.com/threat/TL-2026-2303) — MEDIUM · 2026-09-02
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — HIGH · 2026-08-27

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, CISA KEV, GitHub Security Advisories, public proof-of-concept repositories. Last verified by Threadlinqs on 2026-08-27. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [portal.msrc.microsoft.com](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144)
- [cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf)
- [cert-portal.siemens.com (ssa 966341)](https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf)

**Exploit and proof of concept**

- [exploit-db.com — exploit](https://www.exploit-db.com/exploits/42031/)
- [exploit-db.com — exploit (42030)](https://www.exploit-db.com/exploits/42030/)
- [exploit-db.com — exploit (41891)](https://www.exploit-db.com/exploits/41891/)
- [exploit-db.com — exploit (41987)](https://www.exploit-db.com/exploits/41987/)

**Vulnerability database entry**

- [securitytracker.com — vdb entry](http://www.securitytracker.com/id/1037991)
- [securityfocus.com — vdb entry](http://www.securityfocus.com/bid/96704)

**Other references**

- [ics-cert.us-cert.gov](https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02)
- [packetstormsecurity.com](http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html)
- [packetstormsecurity.com (SMB DOUBLEPULSAR Remote Code Execution)](http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html)

Canonical: https://intel.threadlinqs.com/cve/CVE-2017-0144
Full detection coverage and IOCs for threats exploiting CVE-2017-0144 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
