EXPOSURES › CVE-2017-0143
CVE-2017-0143
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.70
Widespread condemnation and association with a major global event.
Strong association with WannaCry ransomware.
"WannaCry Ransomware Explained | 2017 Attack, Impact & Fixes"
Directly links to a catastrophic event.
"Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution."
Negative association with a list of breached companies.
"5 MI Microsoft 48"
Neutral listing, no judgment.
"Microsoft CVEs and Security Vulnerabilities - OpenCVE"
Neutral listing, no judgment.
"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)."
Neutral listing, no judgment.
"Browse 772 breaches across 20 industries."
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |