CVE•Published 2017-03-17•1 article on news•6 live references•NVD data
CVE-2017-0144
Vulnerability data via CVEDB (Shodan)
CVSS v3.1
8.8
HIGH
EPSS percentile
100
Exploit Prediction Scoring System · top 0% of all CVEs
Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Timeline
Published 2017-03-17
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
Shodan · vuln tag
vuln:CVE-2017-0144Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Microsoft Server Message Block" version:"1.0"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Server Message Block"HTTP body or banner mentions "Server Message Block" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2017-0144Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2017-0144Censys host search filtered to this CVE id.
grep.app
CVE-2017-0144Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2017-0144GitHub code search for direct mentions.
Google dork
"CVE-2017-0144" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (5)
CVE-2017-01445 repos
k8gege/LadonC#
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\S…
infosecn1nja/AD-Attack-Defenseunknown
Attack and defend active directory using modern post exploitation adversary tradecraft activity
0xsyr0/OSCPPowerShell
OSCP Cheat Sheet
GhostTroops/TOPShell
TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.