---
id: CVE-2017-0144
title: >-
  The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and
  R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows
  RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows
  remote …
summary: >-
  The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and
  R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows
  RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows
  remote …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: microsoft
product: server_message_block
affected:
  - server_message_block = 1.0
  - acuson_p300_firmware = 13.02
  - acuson_p300_firmware = 13.03
  - acuson_p300_firmware = 13.20
  - acuson_p300_firmware = 13.21
  - acuson_p500_firmware = va10
  - acuson_p500_firmware = vb10
  - 'acuson_sc2000_firmware >= 4.0, < 4.0e'
  - acuson_sc2000_firmware = 5.0a
  - acuson_x700_firmware = 1.0
  - acuson_x700_firmware = 1.1
  - 'syngo_sc2000_firmware >= 4.0, < 4.0e'
  - syngo_sc2000_firmware = 5.0a
  - tissue_preparation_system_firmware
  - versant_kpcr_molecular_system_firmware
  - versant_kpcr_sample_prep_firmware
patched:
  - acuson_sc2000_firmware 4.0e
  - syngo_sc2000_firmware 4.0e
published: '2017-03-17'
updated: '2026-08-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-0144'
references:
  - url: >-
      http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html
    label: secure@microsoft.com
  - url: >-
      http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html
    label: secure@microsoft.com
  - url: 'http://www.securityfocus.com/bid/96704'
    label: secure@microsoft.com
  - url: 'http://www.securitytracker.com/id/1037991'
    label: secure@microsoft.com
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf'
    label: secure@microsoft.com
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf'
    label: secure@microsoft.com
  - url: 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144
    label: secure@microsoft.com
  - url: 'https://www.exploit-db.com/exploits/41891/'
    label: secure@microsoft.com
  - url: 'https://www.exploit-db.com/exploits/41987/'
    label: secure@microsoft.com
  - url: 'https://www.exploit-db.com/exploits/42030/'
    label: secure@microsoft.com
  - url: 'https://www.exploit-db.com/exploits/42031/'
    label: secure@microsoft.com
  - url: >-
      http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/96704'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1037991'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/41891/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/41987/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/42030/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/42031/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0144
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.9923
epssPercentile: 0.99936
kev: true
kevDateAdded: '2022-02-10'
kevDueDate: '2022-08-10'
kevRansomware: true
exploited: true
exploitAvailable: true
zeroDay: true
ingestedAt: '2026-08-14T06:15:27.437Z'
exploits:
  exploitdb: true
  github: 26
  githubRepos:
    - 'https://github.com/peterpt/eternal_scanner'
    - 'https://github.com/kimocoder/eternalblue'
    - >-
      https://github.com/EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
  metasploit:
    - auxiliary/scanner/smb/smb_ms17_010
    - exploit/windows/smb/ms17_010_eternalblue
    - exploit/windows/smb/smb_doublepulsar_rce
  checkedAt: '2026-09-22T07:10:49.045Z'
---

## Overview

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

## Affected

- `server_message_block = 1.0`
- `acuson_p300_firmware = 13.02`
- `acuson_p300_firmware = 13.03`
- `acuson_p300_firmware = 13.20`
- `acuson_p300_firmware = 13.21`
- `acuson_p500_firmware = va10`
- `acuson_p500_firmware = vb10`
- `acuson_sc2000_firmware >= 4.0, < 4.0e`
- `acuson_sc2000_firmware = 5.0a`
- `acuson_x700_firmware = 1.0`
- `acuson_x700_firmware = 1.1`
- `syngo_sc2000_firmware >= 4.0, < 4.0e`
- `syngo_sc2000_firmware = 5.0a`
- `tissue_preparation_system_firmware`
- `versant_kpcr_molecular_system_firmware`
- `versant_kpcr_sample_prep_firmware`

## Remediation

Upgrade past the affected range:

- `acuson_sc2000_firmware 4.0e`
- `syngo_sc2000_firmware 4.0e`
