CVE-2017-0144 - CVSS 8.8
CVE-2017-0144
Published Date:17 March, 2017 Exploited in the Wild Ransomware UsageNVD-CWE-noinfo
Last modified:14 August, 2026
Link: CVE-2017-0144
NVD: CVE-2017-0144
UBUNTU: CVE-2017-0144
REDHAT: CVE-2017-0144
EUVD: EUVD-2017-0511
Last modified:14 August, 2026
Link: CVE-2017-0144
NVD: CVE-2017-0144
UBUNTU: CVE-2017-0144
REDHAT: CVE-2017-0144
EUVD: EUVD-2017-0511
Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
CVSS Base Score
BASE
8.8
High
CVSS scores for CVE-2017-0144
CVSS v3.1 : 8.8 HIGH
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| User Interaction | None |
CVSS v2 : 9.3 HIGH
| Access Vector | Network |
| Access Complexity | Medium |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
Threat Intelligence
- Has Public Exploit: Yes
- CISA KEV Release Date: 10 February, 2022
- CISA KEV Due Date: 10 August, 2022
- CISA KEV Required Action:
Apply updates per vendor instructions.
Exploit Prediction in the next 30 days
99%
EPSS
Likely Exploited Vulnerabilities Probability
100%
LEV
Common Weakness Enumeration for CVE-2017-0144
NVD-CWE-noinfo
No CWE was provided by the vendor
Products affected by CVE-2017-0144
Configuration 1:
Running on ALL of the following:
Running on:
server_message_block
cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*
Any of the following configurations:
windows_10_1507
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
OR
windows_10_1507
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:*
OR
windows_10_1511
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
OR
windows_10_1511
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x86:*
OR
windows_10_1607
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
OR
windows_10_1607
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*
OR
windows_7
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
OR
windows_8.1
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
OR
windows_rt_8.1
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
OR
windows_server_2008
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
OR
windows_server_2008
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
OR
windows_server_2012
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
OR
windows_server_2012
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
OR
windows_server_2016
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
OR
windows_vista
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
Configuration 2:
Running on ALL of the following:
Any of the following configurations:
acuson_p300_firmware
cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*
OR
acuson_p300_firmware
cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*
OR
acuson_p300_firmware
cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*
OR
acuson_p300_firmware
cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*
Running on:
acuson_p300
cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*
Configuration 3:
Running on ALL of the following:
Any of the following configurations:
acuson_p500_firmware
cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*
OR
acuson_p500_firmware
cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*
Running on:
acuson_p500
cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*
Configuration 4:
Running on ALL of the following:
Any of the following configurations:
acuson_sc2000_firmware
cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*
Version Range:
from 4.0 (including)up to 4.0e (excluding)
OR
acuson_sc2000_firmware
cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*
Running on:
acuson_sc2000
cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*
Configuration 5:
Running on ALL of the following:
Any of the following configurations:
acuson_x700_firmware
cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*
OR
acuson_x700_firmware
cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*
Running on:
acuson_x700
cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*
Configuration 6:
Running on ALL of the following:
Any of the following configurations:
syngo_sc2000_firmware
cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*
Version Range:
from 4.0 (including)up to 4.0e (excluding)
OR
syngo_sc2000_firmware
cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*
Running on:
syngo_sc2000
cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*
Configuration 7:
Running on ALL of the following:
Running on:
tissue_preparation_system_firmware
cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*
Running on:
tissue_preparation_system
cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*
Configuration 8:
Running on ALL of the following:
Running on:
versant_kpcr_molecular_system_firmware
cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:*
Running on:
versant_kpcr_molecular_system
cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*
Configuration 9:
Running on ALL of the following:
Running on:
versant_kpcr_sample_prep_firmware
cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:*
Running on:
versant_kpcr_sample_prep
cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:*
