Skip to main content

CVE detail

CVE-2017-0143

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVSS 8.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
19 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
19 source links · newest first
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • It’s been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.

    exploithorizon3.aiJul 13, 2022, 12:54 PM
  • Hack the Box – BlueHorizon3.ai

    NodeZero exploited EternalBlue on HTB’s Blue machine to gain system access and dump credentials, showing the risk of unpatched SMB vulnerabilities.

    exploithorizon3.aiAug 27, 2021, 7:42 PM
  • The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.

    vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PM
  • Several Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.

    newswww.securityweek.comMay 13, 2020, 4:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →

    newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM
  • UPSynergy: Chinese-American Spy vs. Spy StoryCheck Point Research

    Research By: Mark Lechtik & Nadav Grossman Introduction Earlier this year, our colleagues at Symantec uncovered an interesting story about the use of Equation group exploitation tools by an alleged Chinese group named Buckeye (a.k.a APT3, or UPS team). One of the key findings in their publication was that variants of the Equation tools […]

    vendorresearch.checkpoint.comSep 5, 2019, 1:00 PM
  • China-linked APT group tracked as APT3 was using a tool attributed to the NSA-linked Equation Group more than one year prior to Shadow Brokers leak. China-linked APT group tracked as APT3 (aka Buckeye, APT3, UPS Team, Gothic Panda, and TG-0110) was using a tool attributed to the NSA-linked Equation Group more than one year prior […]

    newssecurityaffairs.comMay 7, 2019, 11:15 AM
  • A Chinese threat actor was spotted using a tool attributed to the NSA-linked Equation Group more than one year prior to it being leaked by the mysterious Shadow Brokers, Symantec revealed on Monday.

    newswww.securityweek.comMay 7, 2019, 6:29 AM
  • A security researcher discovered a new crypto mining worm dubbed ZombieBoy that leverages several exploits to evade detection. The security researcher James Quinn has spotted a new strain of crypto mining worm dubbed ZombieBoy that appears to be very profitable and leverages several exploits to evade detection. The expert called this new malware ZombieBoy because it uses a tool called […]

    newssecurityaffairs.comAug 6, 2018, 5:09 AM
  • A recently discovered crypto-currency mining malware family is using multiple exploits in an attempt to increase its chances of successfully compromising web servers, AlienVault has discovered.

    newswww.securityweek.comMay 3, 2018, 3:58 PM
  • Security researcher Sean Dillon ported three NSA-linked exploits, EternalSynergy, EternalRomance, and EternalChampion, to the Metasploit platform. The security researcher at RiskSense Sean Dillon (@zerosum0x0) ported the Rapid7 Metasploit three hacking tools supposedly stolen from the NSA-linked Equation Group. The researcher modified the exploits to use them also against latest windows versions and merged them into the Metasploit […]

    newssecurityaffairs.comFeb 7, 2018, 7:25 AM
  • Three hacking tools supposedly stolen from the National Security Agency-linked Equation Group and made public last year were recently ported to Rapid7’s Metasploit Framework.

    newswww.securityweek.comFeb 6, 2018, 11:33 AM
  • I’m proud to share with you the first report produced by Z-Lab, the Malware Lab launched by the company CSE CybSec. Enjoy the Analysis Report NotPetya. As most of you already know I have officially presented my new Co a couple of months ago, CybSec Enterprise is its name and we already started to work on […]

    newssecurityaffairs.comSep 18, 2017, 10:39 AM
  • The winners of the 2017 Pwnie Awards were announced last night at the Black Hat USA security conference. The annual ceremony awards the very best and worst coming out of the security community. People previously nominated their opinions of the biggest achievements and failures over the last year; the award winners are chosen from the […]

    newswww.csoonline.comJul 27, 2017, 4:23 PM
  • 2017-7-24 Global Cyber Attack ReportsCheck Point Research

    TOP ATTACKS AND BREACHES A vulnerability in Parity’s Ethereum wallet software has led to the theft of $30M worth of Ethereum cryptocurrency coins. Parity’s wallet software provides Ethereum coins holders the ability to access their wallet comfortably via a web-browser. The vulnerability that was exploited in the attack allowed threat actors to hijack victims’ […]

    vendorresearch.checkpoint.comJul 24, 2017, 5:28 PM
  • A security researcher has devised an EternalSynergy-based exploit that can compromise versions of Windows newer than Windows 8.

    newswww.securityweek.comJul 18, 2017, 4:18 PM
  • Background Rarely does the release of an exploit have such a large impact across the world. With the recent leak of the NSA exploit methods, we saw the effects of powerful tools in the wrong hands. On April 14, 2017, a group known as the Shadow Brokers released a large portion of the stolen […]

    vendorresearch.checkpoint.comMay 25, 2017, 9:39 AM
  • Global Outbreak of WannaCryCheck Point Research

    [Updated May 17, 2017] On May 12, 2017 the Check Point Incident Response Team started tracking a wide spread outbreak of the WannaCryp ransomware. We have reports that multiple global organizations are experiencing a large scale ransomware attack which is utilizing SMB to propagate within their networks. To complicate matters there are a number of […]

    vendorresearch.checkpoint.comMay 12, 2017, 7:08 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence