PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0145 Microsoft CVE debrief

CVE-2017-0145 is listed by CISA in the Known Exploited Vulnerabilities catalog for Microsoft SMBv1 and is marked as having known ransomware campaign use. In the supplied record, CISA added the entry on 2022-02-10 and set a remediation due date of 2022-08-10. Defenders should treat any environment that still relies on SMBv1 as urgent patch-and-mitigate territory and follow vendor guidance to remove or update the vulnerable component.

Vendor
Microsoft
Product
SMBv1
CVSS
HIGH 8.8
CISA KEV
Listed
Original CVE published
2022-02-10
Original CVE updated
2022-02-10
Advisory published
2022-02-10
Advisory updated
2022-02-10

Who should care

Windows administrators, vulnerability management teams, security operations, and incident responders responsible for systems where SMBv1 is still enabled, reachable, or depended on by legacy applications.

Technical summary

The official CISA KEV entry identifies CVE-2017-0145 as a Microsoft SMBv1 remote code execution vulnerability. CISA marks the item as actively exploited and notes known ransomware campaign use. The KEV record directs organizations to apply updates per vendor instructions, and the linked CVE/NVD records provide the canonical vulnerability references.

Defensive priority

Critical

Recommended defensive actions

  • Apply Microsoft vendor updates and follow the remediation guidance referenced by CISA KEV.
  • Identify and inventory any systems or applications that still require SMBv1.
  • Disable SMBv1 wherever it is not strictly required and remove legacy dependencies.
  • Prioritize remediation on exposed, high-value, and internet-reachable assets.
  • Verify remediation by rescanning and confirming SMBv1 is no longer enabled where it should be removed.
  • Monitor for signs of exploitation and ransomware-related activity across affected hosts.

Evidence notes

The supplied corpus contains only official sources. CISA’s Known Exploited Vulnerabilities catalog lists Microsoft SMBv1 / CVE-2017-0145 with known ransomware campaign use and a remediation due date of 2022-08-10. The source item points to the NVD detail page for CVE-2017-0145, and the official CVE record is included as a canonical identifier reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0145 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0145

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0145 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0145

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.