Security readout for executives and security teams
Plain-English summary
CVE-2017-0144 is a serious Windows SMBv1 server flaw that can let an attacker run code on affected Windows systems through crafted network packets. It affects several older Windows client and server releases. CISA lists it in the Known Exploited Vulnerabilities catalog, so this is not theoretical risk.
Executive priority
Treat this as an urgent legacy-risk issue. KEV status and public exploit references mean exposed or unpatched SMBv1 systems can create material business risk, including service disruption and lateral movement. Focus first on internet-facing, business-critical, and operational technology environments.
Technical view
The issue is remote code execution in the SMBv1 server component across listed Microsoft Windows versions. The CVSS 3.1 score is 8.8 with network attack vector, low complexity, no user interaction, and high confidentiality, integrity, and availability impact. Public exploit references exist, but this assessment does not include exploitation details.
Likely exposure
Highest exposure is any affected Windows host with SMBv1 reachable from untrusted networks or flat internal networks. Legacy Windows servers, embedded systems, industrial environments, and unpatched endpoints are the main concern. Evidence in the bundle also includes Siemens and ICS-CERT references, indicating operational technology relevance may exist in some environments.
Exploitation context
Active exploitation is supported by CISA KEV status. The source bundle also includes multiple public exploit database and packetstorm references. That combination makes lingering SMBv1 exposure a high-priority remediation item, especially on internet-facing, partner-connected, or poorly segmented networks.
Researcher notes
The bundle supports Windows SMBv1 RCE, high CVSS impact, affected Microsoft versions, KEV listing, and public exploit references. It does not provide complete patch matrix details or product-specific Siemens impact text, so validation should rely on the linked vendor and government advisories.
Mitigation direction
- Apply Microsoft guidance and security updates for CVE-2017-0144.
- Identify and remove unsupported affected Windows versions where feasible.
- Reduce SMBv1 exposure across network boundaries and untrusted segments.
- Review Siemens and ICS-CERT guidance for affected operational technology products.
- Prioritize remediation on servers, domain-connected assets, and legacy systems.
Validation and detection
- Inventory Windows versions listed in the CVE affected range.
- Check whether SMBv1 server exposure exists on those systems.
- Confirm Microsoft CVE-2017-0144 remediation is installed or otherwise addressed.
- Review network paths that allow SMB access to legacy hosts.
- Validate OT product exposure against Siemens and ICS-CERT advisories.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2017-0144 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.8 (3.1)
- Known Exploited
- Yes
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CISA KEV status
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H2.85.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
8.8HighVector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- 42031CVE reference · exploit, x_refsource_EXPLOIT-DB
- 42030CVE reference · exploit, x_refsource_EXPLOIT-DB
- 41891CVE reference · exploit, x_refsource_EXPLOIT-DB
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144CVE reference · x_refsource_CONFIRM
- https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdfCVE reference · x_refsource_CONFIRM
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02CVE reference · x_refsource_MISC
- 41987CVE reference · exploit, x_refsource_EXPLOIT-DB
- https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdfCVE reference · x_refsource_CONFIRM
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0144CVE reference · government-resource
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
