FAIL › dossier
SMBv1 server
PRODUCT· dossier confidence 90%
SMBv1 is a legacy Microsoft protocol containing critical RCE vulnerabilities actively exploited in ransomware attacks targeting DIB organizations. Its legacy status and lack of modern security patches make it a high-risk attack vector.
PROFILE
Categorylegacy protocolWhat they doSMBv1 is a legacy Microsoft network protocol used for file and printer sharing.
SECURITY POSTURE
Legacy protocol with critical vulnerabilities actively exploited in ransomware attacks.
Notable failures
- CVE-2017-0148 RCE exploited in ransomware
- CVE-2017-0147 data theft exploited in ransomware
Patterns: repeated unpatched edge-device RCEs; legacy protocol vulnerabilities actively exploited in ransomware
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-06 | CVE-2017-0148 | critical | Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers. |
| 2022-05-24 | CVE-2017-0147 | critical | Microsoft's SMBv1 vulnerability (CVE-2017-0147) allowed attackers to steal sensitive data from Windows processes via crafted packets, and was actively exploited in ransomware attacks, demonstrating a critical failure to secure a core Windows component. |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:48:05.677130+00:00