MS17-010 EternalBlue - Detection
MS17-010 is still worth checking when SMBv1 is present because a positive result can indicate a no-credentials remote code execution path on the target.
Confirm SMBv1 first.
If SMBv1 is not present, stop here.
Run the safe Nmap check.
| smb-vuln-ms17-010: | VULNERABLE: | Remote Code Execution vulnerability in Microsoft SMBv1 servers | State: VULNERABLE
If Nmap reports vulnerable, write it as likely vulnerable and keep the exact output. That is enough for a strong discovery finding even if exploitation is out of scope. For exploitation, see EternalBlue MS17-010 SMB RCE. If the Print Spooler is also running, also check PrintNightmare.
Add OS context before final wording.
A legacy Windows family plus SMBv1 plus a positive script result is the combination that matters. If the result is negative, you still keep the SMBv1 finding. If the result is inconclusive, keep the wording conservative instead of overstating it.
References
-
smb-vuln-ms17-010 NSE Scriptnmap.org/nsedoc/scripts/smb-vuln-ms17-010.html (opens in new tab)
Safe MS17-010 detection
-
smb-protocols NSE Scriptnmap.org/nsedoc/scripts/smb-protocols.html (opens in new tab)
Confirm SMBv1 before legacy checks
-
Microsoft Security Bulletin MS17-010learn.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010 (opens in new tab)
Affected SMBv1 vulnerability context
Was this helpful?
Your feedback helps improve this page.