PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0148 Microsoft CVE debrief

CVE-2017-0148 is a Microsoft SMBv1 server remote code execution vulnerability that CISA includes in its Known Exploited Vulnerabilities catalog. The KEV entry indicates known exploitation and notes known ransomware campaign use, so this should be treated as an urgent patching and exposure-reduction item. CISA’s required action is to apply updates per vendor instructions.

Vendor
Microsoft
Product
SMBv1 server
CVSS
HIGH 8.1
CISA KEV
Listed
Original CVE published
2022-04-06
Original CVE updated
2022-04-06
Advisory published
2022-04-06
Advisory updated
2022-04-06

Who should care

Windows security teams, patch management owners, incident responders, and administrators responsible for Microsoft SMBv1 server exposure or legacy SMBv1 dependencies should prioritize this CVE.

Technical summary

According to the supplied official records, CVE-2017-0148 affects Microsoft SMBv1 server and enables remote code execution. CISA lists it in KEV, with a required action to apply vendor updates. The KEV metadata also marks the vulnerability as having known ransomware campaign use.

Defensive priority

Immediate

Recommended defensive actions

  • Apply Microsoft updates per vendor instructions as soon as possible.
  • Verify which systems still rely on SMBv1 and remove or disable SMBv1 where operationally feasible.
  • Prioritize internet-facing and high-value systems that expose SMBv1-related services.
  • Use CISA KEV status to drive emergency patching, validation, and follow-up scanning.
  • Check incident response and detection coverage for systems that may already have been affected.

Evidence notes

This debrief is limited to the supplied official source corpus: CISA KEV metadata, the CVE record, and the NVD detail link. The corpus provides the vulnerability name, affected vendor/product, KEV status, due date, and known ransomware campaign use, but does not include a CVSS score, exploit mechanism details, or remediation specifics beyond CISA’s instruction to apply vendor updates.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0148 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0148

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0148 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0148

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.