AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-0016

MEDIUM · CVSS 5.9 EPSS 23.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-03-17 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. It affects Microsoft, Windows. Its EPSS score suggests a 23.7% probability of exploitation in the next 30 days. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2017-0016
Severity
MEDIUM
CVSS
5.9
EPSS
23.73%
Microsoft Windows

Original NVD Description

Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability."