目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2017-0144— Microsoft Windows SMB 输入验证错误漏洞

一分钟漏洞结论

影响对象
Microsoft Corporation Windows SMB
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Microsoft Windows和Microsoft Windows Server都是美国微软(Microsoft)公司的产品。Microsoft Windows是一套个人设备使用的操作系统。Microsoft Windows Server是一套服务器操作系统。Server Message Block(SMB)Server是其中的一个为计算机提供身份验证用以访问服务器上打印机和文件系统的组件。 Microsoft Windows中的SMBv1服务器存在远程代码执行漏洞。远程攻击者可借助特制的数据包利用该

AI 预测 8.8 利用难度: 较易 KEV · 勒索软件 EPSS 99.23% · P100

影响版本矩阵 1

厂商产品 版本范围状态
Microsoft Corporation Windows SMB The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2017-0144 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows SMB 输入验证错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Microsoft Windows和Microsoft Windows Server都是美国微软(Microsoft)公司的产品。Microsoft Windows是一套个人设备使用的操作系统。Microsoft Windows Server是一套服务器操作系统。Server Message Block(SMB)Server是其中的一个为计算机提供身份验证用以访问服务器上打印机和文件系统的组件。 Microsoft Windows中的SMBv1服务器存在远程代码执行漏洞。远程攻击者可借助特制的数据包利用该
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
Microsoft Corporation Windows SMB The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 -

二、漏洞 CVE-2017-0144 的公开POC

# POC 描述 源链接 神龙链接
1 An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance) https://github.com/peterpt/eternal_scanner POC详情
2 CVE-2017-0144 https://github.com/kimocoder/eternalblue POC详情
3 None https://github.com/EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution POC详情
4 Chương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144 https://github.com/quynhold/Detect-CVE-2017-0144-attack POC详情
5 LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB. https://github.com/ducanh2oo3/Vulnerability-Research-CVE-2017-0144 POC详情
6 CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523 https://github.com/AnugiArrawwala/CVE-Research POC详情
7 Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag.txt file stored in the `C:\Windows\System32` directory. https://github.com/sethwhy/BlueDoor POC详情
8 AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only! https://github.com/AtithKhawas/autoblue POC详情
9 This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB. https://github.com/MedX267/EternalBlue-Vulnerability-Scanner POC详情
10 Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell. https://github.com/pelagornisandersi/WIndows-7-automated-exploitation-using-metasploit-framework- POC详情
11 None https://github.com/luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144 POC详情
12 This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure. https://github.com/AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint POC详情
13 Educational documentation on EternalBlue (CVE-2017-0144) – Windows SMB vulnerability, history, and mitigation. No exploit code. https://github.com/nivedh-j/EternalBlue-Explained POC详情
14 CVE-2017-0144 https://github.com/B1ack4sh/Blackash-CVE-2017-0144 POC详情
15 None https://github.com/AbbeAlthany/Windows-7_och_CVE-2017-0144_Exploit POC详情
16 CVE-2017-0144 https://github.com/Ashwesker/Blackash-CVE-2017-0144 POC详情
17 The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." https://github.com/Mitsu-bis/Eternal-Blue-CVE-2017-0144-THM-Write-Up POC详情
18 CVE-2017-0144 https://github.com/FireTemple/Blackash-CVE-2017-0144 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2017-0144 的情报信息

请登录查看更多情报信息。

CVE-2017-0144 厂商安全公告 (5)

CVE-2017-0144 公开利用代码 (5)

CVE-2017-0144 其他参考 (1)

同批安全公告 · Microsoft Corporation · 2017-03-17 · 共 129 条

CVE-2017-0100 Microsoft Windows COM 权限许可和访问控制漏洞
CVE-2017-0116 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0115 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0114 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0113 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0112 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0111 Microsoft Windows Uniscribe 信息泄露漏洞
CVE-2017-0110 Microsoft Exchange Server 权限许可和访问控制漏洞
CVE-2017-0109 Microsoft Windows Hyper-V 安全漏洞
CVE-2017-0108 多款Microsoft产品Windows Graphics组件缓冲区错误漏洞
CVE-2017-0107 Microsoft SharePoint 跨站脚本漏洞
CVE-2017-0105 Microsoft Office 信息泄露漏洞
CVE-2017-0104 Microsoft Windows iSNS服务器安全漏洞
CVE-2017-0103 Microsoft Windows Registry 权限许可和访问控制漏洞
CVE-2017-0102 Microsoft Windows 权限许可和访问控制漏洞
CVE-2017-0101 Microsoft Windows Transaction Manager 权限许可和访问控制漏洞
CVE-2017-0088 Microsoft Windows Uniscribe 缓冲区错误漏洞
CVE-2017-0087 Microsoft Windows Uniscribe 缓冲区错误漏洞
CVE-2017-0086 Microsoft Windows Uniscribe 缓冲区错误漏洞
CVE-2017-0089 Microsoft Windows Uniscribe 缓冲区错误漏洞

显示前 20 条,共 129 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-0144

暂无评论


发表评论