cbcvebase.
CVE-2017-0146
published 2017-03-17

CVE-2017-0146: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT…

PriorityP198high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
89.86%
99.8th percentile
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftserver_message_block
microsoft_corporationwindows_smb
msrcwindows_10
msrcwindows_10_version_1511
msrcwindows_10_version_1607
msrcwindows_7
msrcwindows_8.1
msrcwindows_rt_8.1
msrcwindows_server_2008
msrcwindows_server_2008_r2
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_vista_service_pack_2
msrcwindows_vista_x64_edition_service_pack_2
philipsintellispace_portal
philipsintellispace_portal
siemensacuson_p300_firmware
siemensacuson_p300_firmware
siemensacuson_p300_firmware
siemensacuson_p300_firmware
siemensacuson_p500_firmware
siemensacuson_p500_firmware
siemensacuson_sc2000_firmware
siemensacuson_sc2000_firmware>= 4.0 < 4.0e4.0e

Detection & IOCsextracted from sources · hover to see the quote

port445
port139
urlhttps://github.com/worawit/MS17-010
urlhttps://hitcon.org/2017/CMT/slide-files/d2_s2_r0.pdf
urlhttps://blogs.technet.microsoft.com/srd/2017/06/29/eternal-champion-exploit-analysis/
sigma
DDI Rule 2722: CVE-2017-0146 - Remote Code Execution - SMB (Request)
  • CVE-2017-0146 (EternalChampion) exploits a race condition in SMBv1 Transaction requests. Detection should focus on anomalous SMB Transaction request patterns on ports 445/139.
  • The exploit requires a named pipe to function; monitor for unexpected named pipe connections over SMB as a detection signal.
  • Trend Micro DDI rule 2722 specifically detects CVE-2017-0146 SMB RCE request traffic; use as a reference signature pattern for network-based detection.
  • Qualys QID 91357 detects EternalChampion (CVE-2017-0146 & CVE-2017-0147) via authenticated scan or Cloud Agent; use as a vulnerability detection reference.
  • The exploit overwrites connection session information to gain Administrator session; monitor for unexpected privilege escalation following SMB connections.
  • The Metasploit module defaults to connecting to the ADMIN$ share; alert on psexec-style service binary uploads to ADMIN$ following SMB exploitation.
  • ·CVE-2017-0146 (EternalChampion) is addressed by MS17-010; unpatched and end-of-life systems (Windows XP, Server 2003) remain vulnerable as no patch is available for those platforms.
  • ·The Metasploit exploit module targets both x86 and x64 Windows architectures; ensure detection coverage spans both.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.