8.1
CVSSv3

CVE-2017-0145

Published: 17/03/2017 Updated: 21/06/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 953
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote malicious users to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft server_message_block 1.0

Exploits

## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## # auxiliary/scanner/smb/smb_ms_17_010 require 'msf/core' class MetasploitModule < Msf::Auxiliary include Msf::Exploit::Remote::SMB::Client include Msf::Exploit::Remote::SMB::Client::Authenticated inc ...
## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote Rank = GreatRanking include Msf::Exploit::Remote::SMB::Client MAX_SHELLCODE_SIZE = 4096 def initialize(info = {}) super(update_info(info, 'N ...
# Exploit Author: Juan Sacco <juansacco@kpncom> at KPN Red Team - wwwkpncom # Date and time of release: May, 9 2017 - 13:00PM # Found this and more exploits on my open source security project: wwwexploitpackcom # # MS17-010 - technetmicrosoftcom/en-us/library/security/ms17-010aspx # Tested on: Microsoft Wind ...

Github Repositories

This is only for information about top hacking tools in termux

This is only for information about top 500 + hacking tools in termux and Linux 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip hack cctv camera version 3 - hack cam IP and ports increase instagram followers - increase your followers, like views instareport - report user on instagram instagram-automation -

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

Contribution guide    Creating a list    Twitter    Follow the My Twitter account for updates on new list additions About this list Hacking made easy with termux android app, nowadays there are so many Pentesters, Security Researchers And Hackers are using termux android app to perform s

This is only for information about top hacking tools in termux

This is only for information about top 500 + hacking tools in termux and Linux 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip hack cctv camera version 3 - hack cam IP and ports increase instagram followers - increase your followers, like views instareport - report user on instagram instagram-automation -

ETERNAL SCANNER 23 Eternal scanner is an network scanner for Eternal Blue exploit CVE-2017-0144 & Eternal Romance (named pipe) CVE-2017-0145 Screenshots 22 Version (New Implementations) Eternal Romance Vulnerability check (escan -er) Escan Database Splited Results (escan -l) Video Eternal Scanner 20 : wwwyoutubecom/watch?v=8heVXfcywq0 Eternal Scann

# TOP-500+-HACKING-TOOLS # SCRIPT BY MONSTER LALLU This is only for information about top 500 + hacking tools in termux and Linux FINDME Instagram account 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip grow follow Is a android app for increase your followers, like views increase instagr

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

Project moving to gitlabcom/peterpt/Eternal_Scanner ETERNAL SCANNER 23 Eternal scanner is an network scanner for Eternal Blue exploit CVE-2017-0144 & Eternal Romance (named pipe) CVE-2017-0145 Screenshots 22 Version (New Implementations) Eternal Romance Vulnerability check (escan -er) Escan Database Splited Results (escan -l) Video Eternal Scanner 2

Termux Nation Repo comes with the full Library, Commands, Configuratios, PFs and Tools For Termux

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

This is only for information about top hacking tools in termux

This is only for information about top 500 + hacking tools in termux and Linux 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip hack cctv camera version 3 - hack cam IP and ports increase instagram followers - increase your followers, like views instareport - report user on instagram instagram-automation -

Cyber-Kunjaali Most power full tools # Cyber-Kunjaali Tools # SCRIPT BY MONSTER LALLU FOR AGORI This is only for information about top 500 + hacking tools in termux and Linux FINDME Instagram account 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip grow follow Is a android app for incr

Config files for my GitHub profile.

Project moving to gitlabcom/peterpt/Eternal_Scanner ETERNAL SCANNER 23 Eternal scanner is an network scanner for Eternal Blue exploit CVE-2017-0144 & Eternal Romance (named pipe) CVE-2017-0145 Screenshots 22 Version (New Implementations) Eternal Romance Vulnerability check (escan -er) Escan Database Splited Results (escan -l) Video Eternal Scanner 2

An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)

ETERNAL SCANNER 23 Eternal scanner is an network scanner for Eternal Blue exploit CVE-2017-0144 & Eternal Romance (named pipe) CVE-2017-0145 Screenshots 22 Version (New Implementations) Eternal Romance Vulnerability check (escan -er) Escan Database Splited Results (escan -l) Video Eternal Scanner 20 : wwwyoutubecom/watch?v=8heVXfcywq0 Eternal Scann

termux_All_hacking_tool This is only for information about top hacking tools in termux FINDME What app: chatwhatsappcom/JtCW38B01hjAGwlVHhyu5q OR chatwhatsappcom/JyqQKyXuw3f43Ll90pHSMO OR chatwhatsappcom/L4iSBfleMKqKd1G10f7IIc Instagram : wwwinstagramcom/

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

# TOP-500+-HACKING-TOOLS # SCRIPT BY MONSTER LALLU This is only for information about top 500 + hacking tools in termux and Linux FINDME Instagram account 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip grow follow Is a android app for increase your followers, like views increase instagr

This is only for information about top hacking tools in termux

This is only for information about top 500 + hacking tools in termux and Linux 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip hack cctv camera version 3 - hack cam IP and ports increase instagram followers - increase your followers, like views instareport - report user on instagram instagram-automation -

Contribution guide    Creating a list    Twitter    Follow the My Twitter account for updates on new list additions About this list Hacking made easy with termux android app, nowadays there are so many Pentesters, Security Researchers And Hackers are using termux android app to perform s

⚡️An awesome list of the best Termux hacking tools

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

Most power full tools

Agori-Baba Most power full tools # Agori-Baba Tools # SCRIPT BY MONSTER LALLU FOR AGORI This is only for information about top 500 + hacking tools in termux and Linux FINDME Instagram account 👉👈 phone number tracker - information gathering tool for phone number GHOSTSPLOIT Connect debug devices via ip grow follow Is a android app for increase you

Install patch for CVE-2017-0145 AKA WannaCry.

Tissues Install patch for CVE-2017-0145 AKA WannaCry More Info: wwwmicrosoftcom/security/portal/threat/encyclopedia/Entryaspx?Name=Ransom:Win32/WannaCrypt Usage: { "name":"my_node", "run_list": [ "recipe[tissues]" ] }

⚡️An awesome list of the best Termux hacking tools

seeker - Accurately Locate Smartphones using Social Engineering findomain - The fastest and cross-platform subdomain enumerator, don't waste your time TekDefense-Automater - Automater - IP URL and MD5 OSINT Analysis BruteX - Automatically brute force all services running on a target Findsploit - Find exploits in local and online databases instantly ReverseAPK - Quick

UPDATING TOOL

seeker - Accurately Locate Smartphones using Social Engineering ANDRAX - ANDRAX is a Penetration Testing platform developed specifically for Android smartphones, ANDRAX has the ability to run natively on Android so it behaves like a common Linux distribution, But more powerful than a common distribution findomain - The fastest and cross-platform subdomain enumerator, don'

Week-16-Homework-Penetration-Testing-1 Step 1: Google Dorking Using Google, can you identify who the Chief Executive Officer of Altoro Mutual is: By navigating to the website demotestfirenet and doing some basic reconnaissance we are able to find out who the CEO of Altoro Mutal is By following the links Inside Altora Mutual > About Us > Executives & Man

Recent Articles

Lazarus: Three North Koreans Charged for Financially Motivated Attacks
Symantec Threat Intelligence Blog • Threat Hunter Team • 18 Feb 2024

More than $1.3 billion stolen in string of attacks against financial institutions and cryptocurrency exchanges.

Posted: 18 Feb, 20214 Min ReadThreat Intelligence SubscribeLazarus: Three North Koreans Charged for Financially Motivated AttacksMore than $1.3 billion stolen in string of attacks against financial institutions and cryptocurrency exchanges. The U.S. government has charged three men in relation to a string of financially motivated cyber attacks linked to the North Korean Lazarus (aka Appleworm) group. The attackers stole approximately $1.3 billion from a ...

Azure users told they're not WannaCrypt-proof
The Register • Richard Chirgwin • 18 May 2017

Microsoft advises how to harden cloudy Windows, cos it runs a cloud not your OS

Microsoft Windows users already know what to do to defeat WannaCrypt (unless they've been asleep for a week). Now the company's published its advice for its Azure customers. Since there aren't any surprises in Microsoft's note for Azure users, Vulture South suspects this is a prod for people who are slow to respond or complacent about security. WannaCrypt is the ransomware/worm built using NSA exploits leaked by Shadow Brokers. It exploits a bug in the ancient and should-have-been-retired SMB1 p...

WannaCrypt ransomware snatches NSA exploit, fscks over Telefónica, other orgs in Spain
The Register • John Leyden • 12 May 2017

EternalBlue now an eternal headache

Updated Workers at Telefónica's Madrid headquarters were left staring at their screen on Friday following a ransomware outbreak. Telefónica was one of several victims of a widespread file-encrypting ransomware outbreak, El Pais reports. Telefónica has confirmed the epidemic on its intranet while downplaying its seriousness, saying everything was under control. Fixed and mobile telephony services provided by the firm have not been affected. Other Spanish targets of the attack reportedly includ...