What CVE identifier was assigned to the 2017 EternalBlue vulnerability?

The story behind the answer

The 2017 EternalBlue vulnerability was assigned the identifier CVE-2017-0144.

EternalBlue targeted a vulnerability in Microsoft's implementation of the Server Message Block version 1 protocol. The flaw allowed specially crafted network traffic to execute code remotely on affected Windows systems. Microsoft issued a security patch in March 2017, before the exploit became widely associated with major malware outbreaks.

The exploit was publicly released in April 2017 by the Shadow Brokers after material attributed to the Equation Group had been stolen. It was later used by WannaCry and NotPetya, although those outbreaks were malware campaigns rather than the vulnerability itself. This distinction matters: EternalBlue was the exploit, while WannaCry was ransomware that used it.

Microsoft eventually disabled SMBv1 in newer Windows configurations because the old protocol had accumulated serious security weaknesses. The incident remains a major example of the danger created when an unpatched network service is exposed at scale.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: