CVE-2017-0148: Microsoft SMBv1 Server Remote Code Execution Vulnerability.
Microsoft SMBv1 Server Remote Code Execution Vulnerability. The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
- CISA KEV-listed (remediation due 2022-04-27)
- used in ransomware campaigns
- EPSS 99.4% (99.9% percentile)
- CVSS 8.1 high
Related briefings
Linked threat actors
- Equation Group machine-inferred link