CVE-2017-0143: Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
Other sources
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0143?
CVE-2017-0143 has been assigned a high severity rating due to its remote code execution capabilities.
How do I fix CVE-2017-0143?
To fix CVE-2017-0143, apply the latest security patches provided by Microsoft for affected Windows versions.
What are the affected systems for CVE-2017-0143?
CVE-2017-0143 affects various versions of Microsoft Windows including Vista, Server 2008, Windows 7 and later versions that include SMBv1.
Can CVE-2017-0143 be exploited remotely?
Yes, CVE-2017-0143 can be exploited remotely, allowing attackers to execute code on affected systems without any user interaction.
Is disabling SMBv1 a solution to mitigate CVE-2017-0143?
Disabling SMBv1 is a recommended mitigation measure for CVE-2017-0143 to reduce exposure to the vulnerability.