RULE(RULE ID:1905426)

Rule General Information
Release Date: 2017-11-21
Rule Name: Microsoft Windows SMB Server SMBv1 Memory Corruption Vulnerability (MS17-010 Eternalblue)(CVE-2017-0144)
Severity:
CVE ID:
Rule Protection Details
Description: A memory corruption vulnerability was found int SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016, which allows remote attackers to execute arbitrary code via crafted packets.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: SecurityFocusBID:96704
SecurityTrackerID:1037991
ExploitDB:42030
ExploitDB:42031
ExploitDB:41891
ExploitDB:41987
Solutions
More information can be found at https://technet.microsoft.com/library/security/ms17-010
https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/