CVE-2017-0144General(microsoft / acuson_p300)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft acuson_p300 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-10. Apply updates per vendor instructions.

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acuson_p300
  • acuson_p300_firmware
  • acuson_p500
  • acuson_p500_firmware

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 22 mentions across 19 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • General: 10 classified signals
  • Peaked 10d ago at 2 mentions (2026-05-15); latest day: 1
  • 22 total mentions across 19 days

Affected systems

Products
acuson_p300acuson_p300_firmwareacuson_p500acuson_p500_firmwareacuson_sc2000acuson_sc2000_firmwareacuson_x700acuson_x700_firmwareserver_message_blocksyngo_sc2000

11 versions affected across 27 products

Deep dive

Activity timeline22 mentions / 19d
01122Mentions · 2026-02-12: 1Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-04-08: 1Mentions · 2026-04-17: 1Mentions · 2026-04-28: 1Mentions · 2026-05-06: 1Mentions · 2026-05-15: 2Mentions · 2026-05-27: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-22: 2Mentions · 2026-06-30: 1Mentions · 2026-08-04: 1Mentions · 2026-08-10: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 2Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-05-15: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-06-11: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-22: 1Technical Details · 2026-08-04: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-14: 102-1203-0503-0703-0804-0804-1704-2805-0605-1505-2706-1106-1206-2206-3008-0408-1009-1309-1410-01
Signal classification4 categories
General
1047.6%
Active Exploitation
838.1%
Patch
29.5%
PoC
14.8%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-03-051
Active Exploitation1
2026-03-071
Active Exploitation1
2026-03-081
General1
2026-04-081
Active Exploitation1
2026-04-171
Active Exploitation1
2026-04-281
General1
2026-05-061
Patch1
2026-05-152
General1PoC1
2026-05-271
Active Exploitation1
2026-06-111
Patch1
2026-06-121
Active Exploitation1
2026-06-222
Active Exploitation1General1
2026-06-301
General1
2026-08-041
Active Exploitation1
2026-08-101
General1
2026-09-131
General1
2026-09-142
General2
Full discourse20 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The text is a brief educational timeline listing notable historical CVEs that shaped the bug bounty landscape, with minimal technical detail and no exploitation, patch, or PoC information for any specific vulnerability.

    31411016411.3K
    3.5K followersView on X
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2017-0144 (EternalBlue) Most impactful Windows vulnerability ever. Affected millions of systems and caused billions in damages worldwide. EternalBlue was a remote code execution flaw in SMBv1. An attacker could send specially crafted network packets and gain code execution without user interaction. It was developed by the NSA and later leaked by Shadow Brokers.

    Post summary

    EternalBlue (CVE-2017-0144) was a remote code execution flaw in SMBv1 that was widely exploited, impacting millions of systems and causing billions in damages worldwide.

    13123102.0K
    4.8K followersView on X
  • 秋津洲@zeki_studydiary

    好きな脆弱性発表ドラゴンが 好きな脆弱性を発表します CVE-2017-0144 CVE-2021-44228 CVE-2023-4863 CVE-2026-31431 正式名称がわからない脆弱性も 好き 好き 大好き

    1202161.4K
    1.4K followersView on X
  • Netomize@Netomize
    General

    We published a follow-up blog showcasing how to detect the famous EternalBlue exploitation vector (CVE-2017-0144) using Yara-X and PacketSmith custom Pattern Identifiers (objects). https://blog.netomize.ca/how-to-detect-eternalblue-exploitation

    Post summary

    The blog post discusses detecting the EternalBlue exploitation vector (CVE‑2017‑0144) with Yara‑X and PacketSmith pattern identifiers, focusing on detection rather than exploitation or remediation.

    0203063
    3 followersView on X
  • CYBER HUB@SOCDefender
    Active Exploitation

    CVE-2017-0144 (EternalBlue) One of the most devastating Windows vulnerabilities. It enabled remote code execution via SMB and fueled the WannaCry ransomware outbreak across the globe. Lesson: Unpatched systems become easy targets. #CVE #EternalBlue #CyberSecurity #InfoSec

    Post summary

    The post highlights that CVE‑2017‑0144, known as EternalBlue, was exploited in the WannaCry ransomware worldwide, underscoring the risk of unpatched systems.

    0102082
    413 followersView on X
  • OS Dev@OSdev_
    General

    https://medium.com/@wangzheyoyo/study-of-cve-2017-0144-eternal-blue-3d6b3f764061

    Post summary

    Based on the single URL provided, no actionable information about the CVE is discernible; the content remains unspecified.

    00021629
    4.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2017-0144 3 - CVE-2026-20820 4 - CVE-2026-29182 5 - CVE-2026-20079 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists trending CVEs without providing any detailed information, claims, or actionable context.

    01020178
    1.7K followersView on X
  • Reelix@Reelix
    General

    @NitinGavhane_ CVE-2017-0144 only being an 8.8 is a crime :(

    Post summary

    The tweet expresses dissatisfaction with the CVSS score of CVE-2017-0144 (8.8), suggesting it should be higher, without providing actionable details or claims of active exploitation or remediation.

    10010216
    482 followersView on X
  • Rıza@rizasabuncu
    General

    @argeolog abi sadece CVE-2017-0144 🤣

    Post summary

    The post only states the CVE identifier, without any additional details or context.

    00020280
    9.1K followersView on X
  • Ashish Rana@AshishRanaX
    PoC

    [ Demonstration Video ] EternalBlue (MS17-010 / CVE-2017-0144) exploitation. Win7 setup from scratch, exploitation using msfconsole, and SMB packet capture with Wireshark. https://youtu.be/50H4OW8W91Y

    Post summary

    A short video demonstrates how to exploit EternalBlue (CVE‑2017‑0144) on Windows 7 using Metasploit with SMB packet capture, serving as a proof of concept.

    1000151
    15 followersView on X
  • BotBauR@BotBauR
    Active Exploitation

    APT28 utiliza técnicas de spear phishing, malware y exploits para vulnerar sistemas. Algunos de los exploits utilizados incluyen CVE-2017-0143, CVE-2017-0144 y CVE-2017-0170. También han utilizado herramientas como malware tipo backdoor, como Sofacy y Zebrocy. APT28 ha utilizado direcciones IP de servidores C2 en Rusia. (3/6)

    Post summary

    The text reports that APT28 actively exploited CVE-2017-0143, CVE-2017-0144, and CVE-2017-0170 in spear‑phishing campaigns, without mentioning PoC, patch, or false‑positive information.

    1001038
    123 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Additional Operational Threats: BlueKeep exploitation: Over 19,000 exposed RDP servers are vulnerable to CVE-2017-0144 (BlueKeep), a nine-year-old RCE flaw actively exploited by multiple threat actor groups. Redheberg botnet: Since February 2026, this malware has infected…

    Post summary

    The snippet confirms that CVE-2017-0144 (BlueKeep) is actively exploited in the wild against over 19,000 exposed RDP servers, but provides no PoC, exploit tools, or patch information.

    1000032
    227 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text is merely a list of Windows CVE identifiers without additional context, details, or actionable information.

    10000106
    15 followersView on X
  • Rohan Rajguru | Linux & Security@rohrathgrat
    General

    @intigriti CVE-2017-0144. It's all blue and happy

    Post summary

    The tweet merely references CVE‑2017‑0144 with no further details or context.

    00010175
    71 followersView on X
  • Grok@grok
    Active Exploitation

    EternalBlue (exploit for Windows SMB zero-day CVE-2017-0144) was developed by the NSA's Equation Group for offensive cyber ops—remote code execution on unpatched systems for espionage/intel gathering. They held it ~5 years without telling Microsoft. Shadow Brokers (hacker group) stole the NSA toolkit & publicly dumped it April 14, 2017 after failed auction attempts. No special "hidden" reason beyond typical nation-state zero-day stockpiling.

    Post summary

    The passage describes the NSA-developed EternalBlue exploit (CVE‑2017‑0144) that was used for remote code execution in espionage activities, and its subsequent public release by Shadow Brokers, indicating ongoing active exploitation.

    00010120
    8.4M followersView on X
  • OFFSECURE@offsecureio
    Active Exploitation

    WannaCry's initial access exploited the SMBv1 protocol using the EternalBlue exploit (CVE-2017-0144). This flaw allowed attackers to send specially crafted packets, enabling unauthorized access to systems running outdated Windows versions.

    Post summary

    The passage confirms that WannaCry leveraged the EternalBlue CVE‑2017‑0144 vulnerability to achieve unauthorized SMB access, indicating real‑world exploitation.

    1000027
    5 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    The text is a historical timeline of high-profile CVEs with generic learning advice for bug bounty hunters, lacking specific technical details, PoCs, exploits, active exploitation reports, or patch information for any individual vulnerability.

    00000121
    19.8K followersView on X
  • Ashish Rana@AshishRanaX
    General

    While exploring the CVE-2017-0144 EternalBlue exploit, I found that msfconsole runs an auxiliary scanner before triggering the exploit. I recreated the vulnerability scanner based on Wireshark network captures from the exploit run. https://ashishranax.com/posts/CVE-2017-0144-Scanner/#python-script

    Post summary

    The author rebuilt a scanner for CVE-2017-0144 based on Wireshark captures, but no new exploit, patch, or active exploitation evidence is presented.

    0000034
    15 followersView on X
  • Proven Data@Proven_Data
    Active Exploitation

    WannaCry exploited CVE-2017-0144 to infect 230,000 systems in 24 hours. Kill-switch-free variants are still active. Full breakdown: https://www.provendata.com/blog/wannacry-ransomware #CyberSecurity #Ransomware #DFIR #WannaCry #IncidentResponse

    Post summary

    The post confirms that WannaCry has actively exploited CVE‑2017‑0144, infecting 230,000 systems in 24 hours, and notes that kill‑switch‑free variants remain a threat, with no mention of PoC, tool, patch or detailed technical info.

    0000044
    909 followersView on X
  • 𝒆𝒏𝒈.@INFJ_100
    Patch

    كيف هزّت ثغرة EternalBlue أسس الأمن الرقمي؟ 💀💻 ثغرة EternalBlue (CVE-2017-0144) واحدة من أكثر الثغرات الكارثية في تاريخ أنظمة التشغيل يكفي انها غيرت مفهوم الأمن الشبكي بالكامل 🚩 شرح فني سريع لهذه الأداة : 🔍 الوصف التقني : الثغرة تضرب بروتوكول SMBv1 (Server Message Block) القديم في ويندوز والمسؤول عن مشاركة الملفات والطابعات تكمن المشكلة في خطأ "فيض المخزن المؤقت" (Buffer Overflow) في نواة النظام (Kernel) 🎮 آلية الاستغلال : 1. المهاجم يرسل حزم بيانات (Packets) مصممة بدقة إلى الـ Target Machine عبر المنفذ (Port 445) 2. بسبب عدم التحقق من المدخلات تجبر هذه الحزم النظام على كتابة بيانات خارج حدود الذاكرة المخصصة لها 3. هذا يسمح بحقن وتمرير أوامر برمجية (Shellcode) مباشرة داخل النواة مما يمنح المهاجم Remote Code Execution (RCE) وصلاحيات كاملة على الجهاز 📈 التأثير : تسريب الأداة من قبل مجموعة Shadow Brokers واستُخدمت في هجمات الفدية الأعنف تاريخياً مثل WannaCry و NotPetya، مشلّةً مستشفيات وبنوك وشركات عالمية 🛡️ الطريقة للإغلاق الجذري : 1. تحديث النظام (Patching) تثبيت التحديث التاريخي MS17-010 فوراَ 2. التعطيل النهائي : إيقاف تفعيل بروتوكول SMBv1 عبر الـ PowerShell : ⁠Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol⁠ 3. مراجعة الجدار الناري : التأكد من إغلاق Port 445 للاتصالات القادمة #الأمن_السيبراني #Cybersecurity

    Post summary

    The post explains EternalBlue’s technical details, notes its real‑world exploitation in major ransomware attacks, and provides clear mitigation steps including the MS17‑010 patch and disabling SMB1.

    00000151
    207 followersView on X
CPE platform detail39 entries

39 of 39 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftserver_message_block1.0--
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1511--x64
OSmicrosoftwindows_10_1511--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_vista---
HWsiemensacuson_p300---
OSsiemensacuson_p300_firmware13.02--
OSsiemensacuson_p300_firmware13.03--
OSsiemensacuson_p300_firmware13.20--
OSsiemensacuson_p300_firmware13.21--
HWsiemensacuson_p500---
OSsiemensacuson_p500_firmwareva10--
OSsiemensacuson_p500_firmwarevb10--
HWsiemensacuson_sc2000---
OSsiemensacuson_sc2000_firmware---
OSsiemensacuson_sc2000_firmware5.0a--
HWsiemensacuson_x700---
OSsiemensacuson_x700_firmware1.0--
OSsiemensacuson_x700_firmware1.1--
HWsiemenssyngo_sc2000---
OSsiemenssyngo_sc2000_firmware---
OSsiemenssyngo_sc2000_firmware5.0a--
HWsiemenstissue_preparation_system---
OSsiemenstissue_preparation_system_firmware---
HWsiemensversant_kpcr_molecular_system---
OSsiemensversant_kpcr_molecular_system_firmware---
HWsiemensversant_kpcr_sample_prep---
OSsiemensversant_kpcr_sample_prep_firmware---

Explore more