7.5

CVE-2017-0147

Warning
Exploit

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1507 Version-
MicrosoftWindows 10 1511 Version-
MicrosoftWindows 10 1607 Version-
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows 8.1 Version-
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server 2008 Version- Updatesp2
MicrosoftWindows Server 2008 Versionr2 Updatesp1
MicrosoftWindows Vista Version- Updatesp2
SiemensAcuson P300 Firmware Version13.02
   SiemensAcuson P300 Version-
SiemensAcuson P300 Firmware Version13.03
   SiemensAcuson P300 Version-
SiemensAcuson P300 Firmware Version13.20
   SiemensAcuson P300 Version-
SiemensAcuson P300 Firmware Version13.21
   SiemensAcuson P300 Version-
SiemensAcuson P500 Firmware Versionva10
   SiemensAcuson P500 Version-
SiemensAcuson P500 Firmware Versionvb10
   SiemensAcuson P500 Version-
SiemensAcuson Sc2000 Firmware Version >= 4.0 < 4.0e
   SiemensAcuson Sc2000 Version-
SiemensAcuson Sc2000 Firmware Version5.0a
   SiemensAcuson Sc2000 Version-
SiemensAcuson X700 Firmware Version1.0
   SiemensAcuson X700 Version-
SiemensAcuson X700 Firmware Version1.1
   SiemensAcuson X700 Version-
SiemensSyngo Sc2000 Firmware Version >= 4.0 < 4.0e
   SiemensSyngo Sc2000 Version-
SiemensSyngo Sc2000 Firmware Version5.0a
   SiemensSyngo Sc2000 Version-

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows SMBv1 Information Disclosure Vulnerability

Vulnerability

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 92.42% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N