CVE-2017-0147

CVE Published 2017-03-17
Related CWE(s) CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Related Vendor(s) microsoft, siemens
Related Product(s) versant_kpcr_sample_prep_firmware, acuson_p300_firmware, acuson_p500_firmware, acuson_sc2000_firmware, acuson_x700_firmware, windows_10_1507, windows_8.1, windows_10_1511, server_message_block, windows_server_2008, versant_kpcr_molecular_system_firmware, windows_vista, windows_server_2016, windows_server_2012, windows_10_1607, syngo_sc2000_firmware, windows_7, windows_rt_8.1, tissue_preparation_system_firmware
Exploitation Reported (CISA KEV) 2022-05-24
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References