Critical SEVERITY — Announcement

EternalBlue archive: SMBv1 completely removed from our environment

The SMBv1 protocol has been permanently disabled across the entire server fleet to mitigate the SMBv1 vulnerability exploited by WannaCry.

Platform
Windows Server
Version
2016
CVE Record
CVE-2017-0144
CVSS Score
9.3/10
Advisory
MS17-010
Published
14 March 2017
Views
5
Primary source: Review the official advisory at msrc.microsoft.com Kaynağa Git

Archive Record

MS17-010 / EternalBlue, a remote code execution vulnerability in the SMBv1 protocol; it was the primary vector for the WannaCry and NotPetya attacks.

Permanent Posture

  • SMBv1 has been removed across our Windows infrastructure using Disable-WindowsOptionalFeature
  • WS2016 and later default to SMBv3 + signing enforced
  • Network scan reports are cross-validated with monthly FortiGate logs

Windows Server — Related Advisories

VIEW ALL →