RULE(RULE ID:1905387)

Rule General Information
Release Date: 2017-04-26
Rule Name: Microsoft Windows SMB Server Smbv1 Memory Corruption Vulnerability -2 (CVE-2017-0143)
Severity:
CVE ID:
Rule Protection Details
Description: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability."
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: SecurityFocusBID:96703
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0143
ExploitDB:41987
SecurityTrackerID:1037991
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://technet.microsoft.com/library/security/MS17-010