← All CVEs

CVE-2017-0143

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

8.8
CVSS
93.3%
EPSS (exploit prob.)
100th
EPSS percentile
2017-03-17
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoftserver_message_block1.0
microsoftwindows_10_1507all versions
microsoftwindows_10_1507all versions
microsoftwindows_10_1511all versions
microsoftwindows_10_1511all versions
microsoftwindows_10_1607all versions
microsoftwindows_10_1607all versions
microsoftwindows_7all versions
microsoftwindows_8.1all versions
microsoftwindows_rt_8.1all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008r2
microsoftwindows_server_2012all versions
microsoftwindows_server_2012r2
microsoftwindows_server_2016all versions
microsoftwindows_vistaall versions
philipsintellispace_portal7.0
philipsintellispace_portal8.0
siemensacuson_p300_firmware13.02
siemensacuson_p300_firmware13.03
siemensacuson_p300_firmware13.20
siemensacuson_p300_firmware13.21
siemensacuson_p300all versions
siemensacuson_p500_firmwareva10
siemensacuson_p500_firmwarevb10
siemensacuson_p500all versions
siemensacuson_sc2000_firmware>= 4.0, < 4.0e
siemensacuson_sc2000_firmware5.0a
siemensacuson_sc2000all versions
siemensacuson_x700_firmware1.0
siemensacuson_x700_firmware1.1
siemensacuson_x700all versions
siemenssyngo_sc2000_firmware>= 4.0, < 4.0e
siemenssyngo_sc2000_firmware5.0a
siemenssyngo_sc2000all versions
siemenstissue_preparation_system_firmwareall versions
siemenstissue_preparation_systemall versions
siemensversant_kpcr_molecular_system_firmwareall versions
siemensversant_kpcr_molecular_systemall versions
siemensversant_kpcr_sample_prep_firmwareall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-0143