ENISA EU KEV catalog membership for CVE-2017-0144
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Vulnerability threat dossier
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
VTP analyst assessment
This CVE remains in monitoring. Its metadata and source evidence are available below. A new material report or relevant sensor finding can trigger an AI review.
The available facts and source references are listed below. No AI assessment has been recorded for this dossier.
No validated baseline evidence scope is persisted for this CVE.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
A validated functional exploit or automated exploitation capability would materially change this assessment.
VTP deterministic assessment
CISA KEV lists this vulnerability as known to be exploited globally.
EPSS is 0.99; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
Claim provenance
1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
CISA lists global known exploitation. This is not a VTP sensor observation.
ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.
Original publications
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.