Skip to content
COOEY

FAIL › dossier

SMBv1 server

PRODUCT

· dossier confidence 90%

SMBv1 is a legacy Microsoft protocol containing critical RCE vulnerabilities actively exploited in ransomware attacks targeting DIB organizations. Its legacy status and lack of modern security patches make it a high-risk attack vector.

PROFILE
Categorylegacy protocolWhat they doSMBv1 is a legacy Microsoft network protocol used for file and printer sharing.
SECURITY POSTURE

Legacy protocol with critical vulnerabilities actively exploited in ransomware attacks.

Notable failures
  • CVE-2017-0148 RCE exploited in ransomware
  • CVE-2017-0147 data theft exploited in ransomware
Patterns: repeated unpatched edge-device RCEs; legacy protocol vulnerabilities actively exploited in ransomware
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-04-06 CVE-2017-0148 critical Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers.
2022-05-24 CVE-2017-0147 critical Microsoft's SMBv1 vulnerability (CVE-2017-0147) allowed attackers to steal sensitive data from Windows processes via crafted packets, and was actively exploited in ransomware attacks, demonstrating a critical failure to secure a core Windows component.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:48:05.677130+00:00