CVE-2017-0147
KEV RANSOMWAREHIGH 7.5EPSS 99.7%
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 99.69% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-05-24, used in ransomware campaigns
- Published
- 2017-03-17
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization…
- http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html
- RobertoLeonFR-ES/Exploit-Win32.CVE-2017-0147.A0★ · 2022-01-04
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/47456
- https://www.exploit-db.com/exploits/43970
- https://www.exploit-db.com/exploits/41891
- https://www.exploit-db.com/exploits/41987