Skip to main content

CVE detail

CVE-2017-0144

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVSS 8.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
44 evidence mentions in the snapshot
Diversity score
20.0
9 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
44 source links · newest first
  • ne Exposure Management Platform showed: 1,865 organizations still exposed to the 2024 vulnerability in Fortinet FortiOS CVE-2024-21762 3,569 organizations still exposed to the 2021 Log4Shell vulnerability CVE-2021-44228 1,430 organizations still exposed to the 2017 WannaCry vulnerability CVE-2017-0144 Moreover, based on aggregated data from more than 1

    vendorwww.tenable.comJun 24, 2026, 1:00 PM
  • WannaCry showed how unpatched flaws and leaked cyber tools can cripple global systems, reshaping cybersecurity defenses worldwide. In memory of the day the digital world was shaken, but learned to fight back. The WannaCry ransomware attack represents one of the most significant events in recent cybersecurity history, not only for its global scale but also […]

    newssecurityaffairs.comMay 12, 2026, 9:31 AM
  • Analyzing evolution of the PipeMagic malwareSecurity Affairs

    Hackers exploited Windows flaw CVE-2025-29824 to deploy PipeMagic malware in RansomExx attacks, Kaspersky revealed. A joint report from Kaspersky and BI.ZONE analyzed the evolution of PipeMagic malware from its first detection in 2022 to new infections observed in 2025. The researchers identified key changes in its operators’ tactics. BI.ZONE experts focused on a technical analysis of the CVE-2025-29824 vulnerability […]

    newssecurityaffairs.comAug 19, 2025, 8:01 AM
  • Scanning and patching aren’t enough. Learn the critical difference between being vulnerable and being exploitable—and why it’s the key to preventing real-world breaches.

    exploithorizon3.aiJun 25, 2025, 1:00 PM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Microsoft has reclassified a Windows vulnerability after an IBM security researcher demonstrated that it can be exploited for remote code execution.

    newswww.securityweek.comDec 16, 2022, 12:46 PM
  • Microsoft revised the severity rate for the CVE-2022-37958 flaw which was addressed with Patch Tuesday security updates for September 2022. Microsoft revised the severity rate for the CVE-2022-37958 vulnerability, the IT giant now rated it as “critical” because it discovered that threat actors can exploit the bug to achieve remote code execution. The CVE-2022-37958 was […]

    newssecurityaffairs.comDec 16, 2022, 6:25 AM
  • Reflecting on the Wannacry ransomware attack, which is the lesson learnt e why most organizations are still ignoring it. In the early afternoon of Friday 12 May 2017, the media broke the news of a global computer security attack carried out through a malicious code capable of encrypting data residing in information systems and demanding […]

    newssecurityaffairs.comOct 31, 2022, 2:37 PM
  • The last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]

    newswww.csoonline.comJul 19, 2022, 9:00 AM
  • The DirtyMoe botnet continues to evolve and now includes a module that implements wormable propagation capabilities. In June 2021, researchers from Avast warned of the rapid growth of the DirtyMoe botnet (PurpleFox, Perkiler, and NuggetPhantom), which passed from 10,000 infected systems in 2020 to more than 100,000 in the first half of 2021. Experts defined DirtyMoe as a […]

    newssecurityaffairs.comMar 21, 2022, 8:03 AM
  • Even in today’s age of digital evolution, malicious hackers continue to use attack vectors dating back decades. Research shows notable periods of resurgence relating to certain methods deemed old-fashioned. What this indicates is that while attack specifics can change with time, points of infection, distribution and proliferation can remain and even lead to the most […]

    newswww.csoonline.comMar 15, 2022, 9:00 AM
  • The U.S. CISA has added to the catalog of vulnerabilities another 15 security vulnerabilities actively exploited in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added fifteen more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that threat actors have abused in attacks […]

    newssecurityaffairs.comFeb 11, 2022, 9:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has added 15 more vulnerabilities to its catalog of flaws that are actively exploited in the wild by hackers. Some are older dating back to 2014, but two are from the past two years and are in Windows components. “These types of vulnerabilities are a frequent attack […]

    newswww.csoonline.comFeb 11, 2022, 8:16 PM
  • A hacking campaign, tracked as Eternal Silence, is abusing UPnP to compromise routers and use them to carry out malicious activities. Researchers from Akamai have spotted a malicious campaign, tracked as ‘Eternal Silence,’ that is abusing Universal Plug and Play (UPnP) to turn routers into a proxy server used to carry out a broad range […]

    newssecurityaffairs.comJan 31, 2022, 7:30 PM
  • Operators behind the Necro Python botnet have added new features to their bot, including VMWare and server exploits. Experts from Cisco Talos have recently observed a new Necro Python bot campaign and noticed that its developers have improved its capabilities. The Necro Python bot, aka FreakOut, has been in development since 2015 and early this […]

    newssecurityaffairs.comJun 4, 2021, 6:17 PM
  • Network attack trends in the Winter quarter of 2020 revealed some interesting trends, such as increased attacker preference for newly released vulnerabilities and a large uptick in attacks deemed Critical. In addition to details of the newly observed exploits, in this blog, we also dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.

    vendorunit42.paloaltonetworks.comApr 12, 2021, 5:37 PM
  • Rudeminer, Blacksquid and Lucifer Walk Into A BarCheck Point Research

    Research by David Driker, Amir Landau Background Lucifer is a Windows crypto miner and DDOS hybrid malware. Three months ago, researchers published a report detailing its unique activities. More recently, we found evidence that the attackers behind this campaign started their operations in 2018. What started as a miner with self-spreading capabilities that targeted the […]

    vendorresearch.checkpoint.comSep 15, 2020, 12:53 PM
  • A recently identified piece of cryptojacking malware includes functionality that enables its operators to launch distributed denial of service (DDoS) attacks, Palo Alto Networks reports.

    newswww.securityweek.comJun 29, 2020, 4:00 AM
  • A new botnet, tracked as Lucifer, appeared in the threat landscape, it leverages close to a dozen exploits to hack Windows systems. A new botnet tracked as Lucifer appeared in the threat landscape, it leverages a dozen exploits for high and critical severity flaws affecting Windows systems. Upon infecting a system the bot turns it […]

    newssecurityaffairs.comJun 26, 2020, 6:40 AM
  • A new hybrid malware capable of cryptojacking and launching DDoS was discovered in the wild, which we've named "Lucifer."

    vendorunit42.paloaltonetworks.comJun 24, 2020, 1:00 PM
  • Researchers uncovered a recent campaign carried out by the InvisiMole group that has been targeting a small number of high-profile organizations. Security researchers at ESET recently uncovered a campaign carried out by the InvisiMole group that has been targeting a small number of high-profile organizations in the military sector and diplomatic missions in Eastern Europe. […]

    newssecurityaffairs.comJun 18, 2020, 8:13 PM
  • In a recent campaign, the elusive InvisiMole group has been targeting a small number of high-profile organizations in the military sector and diplomatic missions in Eastern Europe, ESET reports.

    newswww.securityweek.comJun 18, 2020, 11:12 AM
  • Ryuk. A name once unique to a fictional character in a popular Japanese comic book and cartoon series is now a…

    newswww.malwarebytes.comDec 11, 2019, 5:00 PM
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • 23rd September – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd September 2019, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES Misconfigured Elasticsearch server holding personal information of more than 20 million Ecuadorian citizens has been found The server, located in Miami and owned by the Ecuadorian company Novaestrat, exposes full PII […]

    vendorresearch.checkpoint.comSep 23, 2019, 3:40 PM
  • Chinese Cyber-Spies Target Government Organizations in Middle East Chinese APT group Emissary Panda has been targeting government organizations in two different countries in the Middle East. Experts at Palo Alto Networks reported that the Chinese APT group Emissary Panda (aka APT27, TG-3390, Bronze Union, and Lucky Mouse) has been targeting government organizations in two different […]

    newssecurityaffairs.comMay 30, 2019, 8:48 AM
  • Chinese cyber-espionage group Emissary Panda has been targeting government organizations in two different countries in the Middle East, Palo Alto Networks security researchers say.

    newswww.securityweek.comMay 29, 2019, 3:23 PM
  • Our latest research shows attacks against Middle East government Sharepoint servers using a newly patched vulnerability. In our blog, we provide details of the tools and tactics, explain how we believe these connect to the Emissary Panda threat group, correlate our findings with those of the Saudi Arabian National Cyber Security Center and the Canadian Center for Cyber Security, and provide indicators of compromise (IoCs) from our research.

    vendorunit42.paloaltonetworks.comMay 28, 2019, 1:00 PM
  • A Quarter Million Devices Vulnerable to UPnProxy Botnet More than 270,000 Internet-connected devices run vulnerable implementations of UPnP and are susceptible to becoming part of a multi-purpose botnet, Akamai says.

    newswww.securityweek.comNov 30, 2018, 8:15 PM
  • Security experts from Kaspersky Lab have spotted a new cryptocurrency miner dubbed PowerGhost that can spread leveraging a fileless infection technique. The PowerGhost miner targets large corporate networks, infecting both workstations and servers, it employing multiple fileless techniques to evade detection. “The malware, which we dubbed PowerGhost, is capable of stealthily establishing itself in a system and spreading […]

    newssecurityaffairs.comJul 31, 2018, 5:40 AM
  • The PowerGhost crypto-miner is capable of remaining undetected on infected systems, and can spread on its own by leveraging a fileless infection technique, Kaspersky Lab has discovered.

    newswww.securityweek.comJul 30, 2018, 2:53 PM
  • Focused on mining Monero crypto-currency, a new botnet has managed to ensnare over half a million machines to date, Proofpoint reports.

    newswww.securityweek.comFeb 2, 2018, 10:39 AM
  • Researchers from Proofpoint discovered a huge botnet dubbed ‘Smominru’ that is using the EternalBlue exploit to infect Windows computers and recruit them in Monero cryptocurrency mining activities. The number of cyber attacks against the cryptocurrency sector continues, vxers are focusing their efforts on the development of cryptocurrency/miner malware. Recently security experts observed cryptocurrency miners leveraging the NSA EternalBlue SMB exploit […]

    newssecurityaffairs.comFeb 1, 2018, 11:46 AM
  • A new report from MALWAREBYTES titled “Malwarebytes Annual State of Malware Report” reveals a rise of 90% on ransomware detection in business. The report brings to light new trends on hackers activities and threats especially the rise of ransomware as a tool of choice. Researchers from MALWAREBYTES had gathered an enormous amount of data from […]

    newssecurityaffairs.comJan 29, 2018, 8:54 AM
  • Cybercriminals and nation state groups were quick to adopt the most effective exploits last year, a new AlienVault report reveals.

    newswww.securityweek.comJan 17, 2018, 3:34 PM
  • There’s a saying that you can’t improve something you don’t measure. It’s also easy to get seduced into believing you’re good at something by measuring how you perform against a poor simulation of the real thing. There are many different tests you can run to assess your readiness to face an attack. To prevent being […]

    newswww.csoonline.comDec 12, 2017, 3:37 PM
  • EternalBlue – Everything There Is To KnowCheck Point Research

    Research By: Nadav Grossman Introduction Since the revelation of the EternalBlue exploit, allegedly developed by the NSA, and the malicious uses that followed with WannaCry, it went under thorough scrutiny by the security community. While many details were researched and published, several remained in the dark, and an end-to-end explanation of the vulnerability and exploit […]

    vendorresearch.checkpoint.comSep 29, 2017, 7:42 PM
  • 2017-7-10 Global Cyber Attack ReportsCheck Point Research

    TOP ATTACKS AND BREACHES Security researchers have found an unsecured Amazon S3 server belonging to the World Wrestling Entertainment (WWE), which led to the possible exposure of sensitive data of over 3 million registeredusers. The researchers have also found a second database that included statistical marketing data. The South Korean cryptocurrency exchange, Bithumb, has […]

    vendorresearch.checkpoint.comJul 10, 2017, 11:18 PM
  • Background In the wake of WannaCry, a new cyber threat has emerged from the NSA leak. Making use of previously exposed tools, Petya once again is engaged in another large scale attack. Important distinctions in this case, however, are that the attacks targeted mainly a specific country, and are used solely for destruction. While […]

    vendorresearch.checkpoint.comJul 3, 2017, 5:58 PM
  • This Unit 42 blog provides an update on the threat situation surrounding attacks using the Petya Ransomware which are impacting organizations in Ukraine and other parts of Europe.

    vendorunit42.paloaltonetworks.comJun 27, 2017, 4:30 PM
  • 2016 was the year of ransomware. Or was it the year of the high-profile break in? It was also the year of the IoT DDoS attack. And even the year of high stakes, political cyber-espionage. Regardless of how you want to label it, we can all agree that 2016 set a new bar for high-profile […]

    newswww.csoonline.comJun 6, 2017, 1:00 PM
  • Background Rarely does the release of an exploit have such a large impact across the world. With the recent leak of the NSA exploit methods, we saw the effects of powerful tools in the wrong hands. On April 14, 2017, a group known as the Shadow Brokers released a large portion of the stolen […]

    vendorresearch.checkpoint.comMay 25, 2017, 9:39 AM
  • This Unit 42 blog provides an update on the threat situation surrounding the WanaCrypt0r ransomware attacks. It also well as information on the adversary playbook this attack uses.

    vendorunit42.paloaltonetworks.comMay 16, 2017, 10:18 PM
  • Global Outbreak of WannaCryCheck Point Research

    [Updated May 17, 2017] On May 12, 2017 the Check Point Incident Response Team started tracking a wide spread outbreak of the WannaCryp ransomware. We have reports that multiple global organizations are experiencing a large scale ransomware attack which is utilizing SMB to propagate within their networks. To complicate matters there are a number of […]

    vendorresearch.checkpoint.comMay 12, 2017, 7:08 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence