EMZETT.
Login

EternalBlue

In short: EternalBlue is an exploit for a hole in the Windows protocol SMBv1 that became known in 2017 through the leak of an intelligence archive.

In more detail: The hole has the number CVE-2017-0144 (Microsoft patch MS17-010). The group “Shadow Brokers” published the exploit in April 2017; it is said to come from the NSA.

In Depth

Impact

It powered the worms WannaCry and NotPetya (environment of GoldenEye). Both spread through networks without user action.

Lesson

Install patches in time, switch off SMBv1, segment networks, do not expose port 445 to the internet. See exploit, worms.

See also: WannaCry, Exploit, Worms, GoldenEye