Vulnerability threat dossier

CVE-2017-0143

microsoftserver message block

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

VTP deterministic threat68.2of 100 · CVSS excluded

VTP analyst assessment

Microsoft Windows SMBv1 remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists CVE-2017-0143 as exploited globally and associated with ransomware campaigns. Crafted SMBv1 packets can enable remote code execution on affected Windows systems. Greenbone also lists public exploit-oriented template coverage.

Why it matters

  • An attacker able to reach a vulnerable SMBv1 server can execute arbitrary code.
  • CISA's ransomware designation makes exposed or unpatched affected systems a high-priority defensive concern.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The bundle does not identify affected customer systems or current targeting.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you run the affected Windows versions, apply Microsoft's remediation and disable SMBv1 where operationally possible.

AI baseline history (1)
  1. BASELINE ASSESSED
    Microsoft Windows SMBv1 remote code executiongpt-5.6-terra · low
Technical severityHIGHCVSS 8.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.93100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.93; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:827cc1f18290db13b26d4474eb1ff0ebe7cf8fd8ACTIVE
04

Event history

Threat timeline

  1. 02:3525 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 00:0003 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 23 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 23 CVEs in this pinned revision. 23 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2015-8279CVE-2015-8280CVE-2015-8281CVE-2017-0143CVE-2017-0144CVE-2017-0145CVE-2017-0146CVE-2017-0147CVE-2017-0148CVE-2017-14083CVE-2017-14084CVE-2017-14085CVE-2017-14086CVE-2017-14087CVE-2017-14088CVE-2017-14089CVE-2017-14396CVE-2017-16524CVE-2017-5227CVE-2017-6359CVE-2017-6360CVE-2017-6361CVE-2017-9328
Separate evidence group
06

Technical vulnerability data

Context, not threat proof

VTP threat score68.2vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction18.66 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Unknown
CPE records
41
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.