CISA Known Exploited Vulnerability

CVE-2017-0147 Ransomware

Microsoft · SMBv1 server

Microsoft Windows SMBv1 Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-200
Ransomware Known

CISA description

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

Required action

Apply updates per vendor instructions.