2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2017-0148" ,
"sourceIdentifier" : "secure@microsoft.com" ,
"published" : "2017-03-17T00:59:04.150" ,
2025-02-11 19:04:39 +00:00
"lastModified" : "2025-02-11T17:01:39.333" ,
"vulnStatus" : "Analyzed" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146."
} ,
{
"lang" : "es" ,
"value" : "El servidor SMBv1 en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; y Windows 10 Gold, 1511 y 1607; y Windows Server 2016 permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de paquetes manipulados, vulnerabilidad tambi\u00e9n conocida como \"Windows SMB Remote Code Execution Vulnerability\". Esta vulnerabilidad es diferente a la descrita en CVE-2017-0143, CVE-2017-0144, CVE-2017-0145 y CVE-2017-0146."
}
] ,
"metrics" : {
2024-07-09 20:03:11 +00:00
"cvssMetricV31" : [
2023-04-24 12:24:31 +02:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
2024-07-09 20:03:11 +00:00
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-11-23 07:09:57 +00:00
"baseScore" : 8.1 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-11-23 07:09:57 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 5.9
2025-02-10 19:03:49 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 8.1 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 5.9
2023-04-24 12:24:31 +02:00
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C" ,
2024-11-23 07:09:57 +00:00
"baseScore" : 9.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-11-23 07:09:57 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
2024-11-23 07:09:57 +00:00
"cisaExploitAdd" : "2022-04-06" ,
"cisaActionDue" : "2022-04-27" ,
"cisaRequiredAction" : "Apply updates per vendor instructions." ,
"cisaVulnerabilityName" : "Microsoft SMBv1 Server Remote Code Execution Vulnerability" ,
2023-04-24 12:24:31 +02:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
2025-02-11 19:04:39 +00:00
"value" : "NVD-CWE-noinfo"
2023-04-24 12:24:31 +02:00
}
]
2025-02-10 19:03:49 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-20"
}
]
2023-04-24 12:24:31 +02:00
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EFFA22FC-A15A-4EB5-BED7-45F6EAFA8F80"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
2024-07-09 20:03:11 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "542DAEEC-73CC-46C6-A630-BF474A3446AC"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-07-09 20:03:11 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7A8E9D99-BD78-4340-88F2-5AFF27AC37C9"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-07-09 20:03:11 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "61019899-D7AF-46E4-A72C-D189180F66AB"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "C2B1C231-DE19-4B8F-A4AA-5B3A65276E46"
} ,
{
"vulnerable" : false ,
2024-07-09 20:03:11 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E93068DB-549B-45AB-8E5C-00EB5D8B5CF8"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C6CE5198-C498-4672-AF4C-77AB4BE06C5C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F422A8C-2C4E-42C8-B420-E0728037E15C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "2ACA9287-B475-4AF7-A4DA-A7143CEF9E57"
} ,
{
"vulnerable" : false ,
2024-07-09 20:03:11 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A7DF96F8-BA6A-4780-9CA3-F719B3F81074"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB18C4CE-5917-401E-ACF7-2747084FD36E"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "041FF8BA-0B12-4A1F-B4BF-9C4F33B7C1E7"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF1AD1A1-EE20-4BCE-9EE6-84B27139811C"
}
]
}
]
2024-07-09 20:03:11 +00:00
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0814F7B8-8022-4DCC-BE37-4868EB912881"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "87A45473-9558-4165-949B-D63F1486F28E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "59E3D131-8FDF-424C-9BBA-41FDAE43F24C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2C270FA0-6961-4181-8388-E609DAEADC09"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C07C8A47-9E8F-42E4-BB35-64590853A9C5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "506F5373-3C3C-4F47-8FC0-D5F04095B324"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "42DBCB0C-2C71-4427-ADF8-FCB4920609B7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3C50335A-8742-4E2B-B22D-0ED0A0DFB5C4"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.0" ,
"versionEndExcluding" : "4.0e" ,
"matchCriteriaId" : "D4CFBFA2-BDE4-4566-A435-92BFB87C48E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7DFBC156-20D1-4546-948F-A2118D602137"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "70575FD4-0A0A-4D11-9069-F808D9F00D10"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1E644CD-EA9B-45B5-A7C6-5F294D8A6909"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4F38DAB6-39E2-4048-A57D-C3EB8415F3F2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "05BD2983-B780-46F0-A857-CFC614D1B524"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.0" ,
"versionEndIncluding" : "4.0e" ,
"matchCriteriaId" : "31FE05B1-0B85-424F-9F30-14BFCB2ED15D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1753DB4B-1F5A-4193-A50C-C2A576F0884C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "25CEAC4F-CBA5-41BA-B389-4D0DA3F85B59"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6DE83393-E735-42BC-86E9-5DAF9F403C73"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5641B967-9938-4148-90C4-D92C3E757847"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "582D4D5C-D0F1-403D-8687-3F1491943A65"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68FE5E09-78BB-4A22-9CAA-93ECD7AC33A4"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:versant_kpcr_sample_prep_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AA7B7CC4-E89E-4357-A7D6-AF74480F46B5"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:versant_kpcr_sample_prep:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "41EF3913-CD35-49FD-90D8-62228DB1390C"
}
]
}
]
2023-04-24 12:24:31 +02:00
}
] ,
"references" : [
{
"url" : "http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://www.securityfocus.com/bid/96706" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://www.securitytracker.com/id/1037991" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148" ,
"source" : "secure@microsoft.com" ,
"tags" : [
2024-07-09 20:03:11 +00:00
"Patch" ,
2023-04-24 12:24:31 +02:00
"Vendor Advisory"
]
} ,
{
"url" : "https://www.exploit-db.com/exploits/41891/" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://www.exploit-db.com/exploits/41987/" ,
2024-07-09 20:03:11 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
2024-11-23 07:09:57 +00:00
} ,
{
"url" : "http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://packetstormsecurity.com/files/156196/SMB-DOUBLEPULSAR-Remote-Code-Execution.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/96706" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1037991" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://www.exploit-db.com/exploits/41891/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://www.exploit-db.com/exploits/41987/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
}
]
}