NOOB2ROOT

CVE watch CVE-2017-0144 Known exploited

EternalBlue: RCE in SMBv1

A flaw in Microsoft SMBv1 allowed remote code execution from a crafted packet. Weaponised by WannaCry and NotPetya into some of the costliest malware outbreaks on record.

Severity
8.1
high
Vendor
Microsoft
Disclosed
14 Mar 2017
Affected
Windows (SMBv1)

CVSS breakdown

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Analysis

Placeholder analysis — replace before publishing.

References