Coming soon on InfoWorld
[See the full post at: Proof of Concept code for SMBv3 zero-day leads to Blue Screens, maybe worse]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Proof of Concept code for SMBv3 zero-day leads to Blue Screens, maybe worse
Home » Forums » Newsletter and Homepage topics » Proof of Concept code for SMBv3 zero-day leads to Blue Screens, maybe worse
- This topic has 18 replies, 8 voices, and was last updated 8 years, 2 months ago by
anonymous.
AuthorTopicViewing 8 reply threadsAuthorReplies-
WildBill
AskWoody PlusFebruary 3, 2017 at 12:11 pm #87357Thanks & Danke schoen to Gunter Born! He’s probably right that PC’s on WAN’s may be vunerable & not LAN’s or WLAN’s. I haven’t been bitten on public Wi-Fi… Yet.
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again... -
anonymous
Guest -
woody
ManagerFebruary 3, 2017 at 12:45 pm #87408I’m certain it’ll be patched. I expect MS to issue a security alert any minute.
What servers? I don’t know. But the Proof of Concept code is straightforward, and available on Github. That means it’s probably already in script kiddie packages.
See https://twitter.com/dangoodin001/status/827557860687044608
-
ch100
AskWoody_MVPFebruary 3, 2017 at 1:35 pm #87485Windows 7 does not use SMB3.
If you are not in a network using file shares, you would not be directly affected.
However, good practice require blocking access from the internet to ports 137, 138, 139 and 445 and most ISPs already provide this functionality by default. Many routers also enable this port blocking as basic firewall rule.
Also you should keep the system fully patched as it is not known if a previous patch mitigates the problem or if systems other than those already documented are affected.
Best effort is always better than inaction. -
anonymous
Guest
-
-
Noel Carboni
AskWoody_MVPFebruary 3, 2017 at 1:22 pm #87452I wonder how many people realize that “connect to an infected server”, in the context of this report, doesn’t mean the kinds of things most folks do online.
SMB is the protocol Windows uses for file and printer sharing.
Unless I’m missing something that other people do that I never do (using OneDrive maybe?), these are not the kinds of connections I *ever* make with “online” servers. Instead, these are the connections enterprises use in their private networks (e.g., to see files on \\SERVER\SHARE). I do use this protocol inside my company network. But of course I have protections against my internal servers being compromised.
To put it succinctly, the “server” described that has to be compromised is not just any old web server that sends people web pages, but generally one which is inside a company or private network offering file and printer sharing.
To not be specific about this seems to spread some unwarranted Fear, Uncertainty, and Doubt.
https://en.wikipedia.org/wiki/Server_Message_Block
Please, someone enlighten me as to whether there’s some component to this I’m not thinking of (e.g., under the covers in OneDrive, Skype, or one of the cloud integrations in the newer versions of Windows?).
-Noel
-
PKCano
Manager -
ch100
AskWoody_MVPFebruary 3, 2017 at 1:47 pm #87496A lot of people use an internal server for file sharing, but most use an “appliance”, which is a black box running a flavour of Linux hidden from the user by a fancy GUI.
We don’t know at this stage if Linux is affected or which NAS appliances are running SMB3.Anyone remember Blaster?
It looks like this is the same style of 0-day attack on port 445.
-
woody
ManagerNoel Carboni
AskWoody_MVPFebruary 3, 2017 at 2:09 pm #87553I use SMB to connect to my NAS drive from my Mac. A NAS drive is actually a server.
Right. And in your case your NAS drive would have to be compromised in order for your Windows system(s) to be affected by this issue. As ch100 points out, we’re not being told how – or if – that could be done.
This isn’t at all the same as connecting to any old web server with a web browser.
I’m concerned that people – who might never have had enterprise computing experience or who simply don’t understand all the complexities of networking – could read more into it than there is and look in the wrong directions or just become unnecessarily upset. Computers don’t just “connect to servers” in one way. This is a case where details matter.
Yes, I suppose you could say that any security threat that keeps online safety in the minds of the masses could be a Good Thing…
But the thing is, incompletely stated/understood threat reports – especially those described as “zero day” – can cause people to make rash decisions. Always think about things first, and seek knowledge before acting. It’s kind of a computer version of “measure twice, cut once”.
-Noel
fp
AskWoody Lounger-
woody
Manager
PKCano
ManagerFebruary 4, 2017 at 5:16 am #88849Naw, not a chance. Sounds like MS was warned, didn’t react quickly enough, and got snowbagged. See the Ars Technica report.
Typical for M$
Goofy
AskWoody LoungerNoel Carboni
AskWoody_MVPFebruary 4, 2017 at 7:17 am #88949ANOTHER UPDATE: Last night, Microsoft Program Manager Ned Pyle tweeted “Yes, fix is coming. I’m not allowed to say more, because Microsoft.”
We can only hope they’re not rushing it out. Much as a quick response seems necessary, it’s still important to get it right.
- They need to completely fix the problem.
- They need to not break anything new.
- They need to maintain system performance.
That’s not always easy to accomplish. We all imagine in our best hopes that it could be a simple matter of adding a line of code to compare a length field – something that requires almost no extra compute time – and voila, bug fixed. But the reality is, depending on the bug, a part of the system may need to be re-designed.
I only bring this up at all because Microsoft has been changing the way they deliver their work to us. Today – presumably in the name of lowering costs – we’re getting software that’s been through fewer and fewer reviews and tests. From the engineers’ desks to ours. Some Windows 10 releases were built literally only a few days before becoming available to the public. There’s clearly not the professional testing being done inside Microsoft that there once was. I can’t help but think this new philosophy of quick and continuous software delivery might also influence changes to the older systems we all rely on, and as a career software engineer that worries me.
In today’s fast moving world we need to trust patches to keep us safe, but we also need to be careful not to allow Microsoft’s questionable policies to break the systems we rely upon. Woody’s MS-DEFCON system is likely more meaningful now than ever before.
-Noel
1 user thanked author for this post.
-
PKCano
Manager
anonymous
GuestFebruary 6, 2017 at 7:52 am #91516Noel Carboni
AskWoody_MVPFebruary 4, 2017 at 7:24 am #88950Even if it didn’t happen, it’s pretty clear that people expect it to happen.
That’s the downside of acting like a predator. People lose trust. Better get used to it – that trust is not coming back soon.
Good morning – there IS a downside to using up a company’s reputation in the name of Marketing.
-Noel
Viewing 8 reply threads - This topic has 18 replies, 8 voices, and was last updated 8 years, 2 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
1 hour, 44 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
2 hours, 26 minutes ago -
Win11 24H4 Slow!
by
Bob Bible
2 hours, 37 minutes ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
1 hour, 57 minutes ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
4 hours, 47 minutes ago -
‘Minority Report’ coming to NYC
by
Alex5723
56 minutes ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
13 hours, 29 minutes ago -
Tracking content block list GONE in Firefox 138
by
Bob99
12 hours, 53 minutes ago -
How do I migrate Password Managers
by
Rush2112
3 hours, 39 minutes ago -
Orb : how fast is my Internet connection
by
Alex5723
10 hours, 26 minutes ago -
Solid color background slows Windows 7 login
by
Alex5723
1 day, 1 hour ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
23 hours, 39 minutes ago -
Security fixes for Firefox
by
Susan Bradley
7 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
1 day, 11 hours ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
1 day, 20 hours ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
1 day, 11 hours ago -
Return of the brain dead FF sidebar
by
EricB
23 hours, 8 minutes ago -
Windows Settings Managed by your Organization
by
WSDavidO61
2 hours, 10 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
8 hours, 2 minutes ago -
The local account tax
by
Susan Bradley
1 day ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
2 days, 9 hours ago -
Digital TV Antenna Recommendation
by
Win7and10
2 days, 2 hours ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
2 days, 21 hours ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
2 days, 23 hours ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
3 days, 2 hours ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
2 days, 5 hours ago -
Steps to take before updating to 24H2
by
Susan Bradley
3 hours, 3 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
2 days, 9 hours ago -
Replacing Skype
by
Peter Deegan
1 day, 22 hours ago -
FileOptimizer — Over 90 tools working together to squish your files
by
Deanna McElveen
2 days, 20 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.