PatchSiren cyber security CVE debrief
CVE-2017-0143 Microsoft CVE debrief
CVE-2017-0143 is a Microsoft Windows Server Message Block (SMBv1) remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use. For defenders, this is a high-priority patching and exposure-reduction item for any environment that still has SMBv1 enabled or reachable.
- Vendor
- Microsoft
- Product
- Windows
- CVSS
- HIGH 8.1
- CISA KEV
- Listed
- Original CVE published
- 2021-11-03
- Original CVE updated
- 2021-11-03
- Advisory published
- 2021-11-03
- Advisory updated
- 2021-11-03
Who should care
Windows administrators, endpoint and server security teams, vulnerability management teams, and incident responders should prioritize this CVE, especially in environments that still support or expose SMBv1.
Technical summary
The vulnerability is identified as a Microsoft Windows SMBv1 remote code execution issue. The supplied source corpus does not provide attack mechanics, affected build ranges, or CVSS scoring. CISA’s KEV catalog indicates the issue is known to be exploited in the wild and associated with known ransomware campaign use, so defenders should treat it as an active risk rather than a purely theoretical flaw.
Defensive priority
Critical for environments with SMBv1 present or exposed. Because CISA lists the CVE as known exploited and tied to ransomware campaign use, remediation should be expedited ahead of routine patch cycles.
Recommended defensive actions
- Apply updates per Microsoft vendor instructions.
- Identify and remove or disable SMBv1 wherever it is not strictly required.
- Prioritize patching and exposure review on Internet-facing and high-value Windows systems.
- Validate that vulnerability management and incident response teams are tracking this CVE as a known exploited item.
- Use the CISA KEV catalog as the operational reference for remediation urgency.
Evidence notes
Timing context: the supplied CVE and source metadata both use 2021-11-03 as the publication/record date in this corpus, and the CISA KEV entry sets dateAdded to 2021-11-03 with dueDate 2022-05-03. Evidence is limited to the official CVE record, NVD detail page, and CISA KEV source. The source corpus explicitly states known ransomware campaign use and requiredAction: Apply updates per vendor instructions.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0143 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0143
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0143 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0143
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.