EternalBlue, sometimes stylized as ETERNALBLUE, is an exploit generally believed to have been developed by the U.S. National Security Agency (NSA). It was leaked by the Shadow Brokers hacker group on 14 April 2017, and was used as part of the worldwide WannaCry ransomware attack on 12 May 2017.
EternalBlue exploits a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol. This vulnerability is denoted by entry CVE-2017-0144 in the Common Vulnerabilities and Exposures (CVE) catalog. The vulnerability exists because the SMB version 1 (SMBv1) server in various versions of Microsoft Windows accepts specially crafted packets from remote attackers, allowing them to execute arbitrary code on the target computer.
The Windows security update on 14 March 2017 resolved the issue via security update MS17-010, for all Windows versions that were currently supported at that time, these being Windows Vista, Windows 7, Windows 8.1, Windows 10, Windows Server 2008, Windows Server 2012, and Windows Server 2016.
On 13 May 2017, a day after the attack, Microsoft took the highly unusual step of also providing a security update for Windows XP, Windows 8, and Windows Server 2003 via download from the Microsoft Update Catalog.
- "NSA-leaking Shadow Brokers just dumped its most damaging release yet". Retrieved 13 May 2017.
- Fox-Brewster, Thomas. "An NSA Cyber Weapon Might Be Behind A Massive Global Ransomware Outbreak". Forbes. Retrieved 13 May 2017.
- "An NSA-derived ransomware worm is shutting down computers worldwide". Ars Technica. Retrieved 13 May 2017.
- Ghosh, Agamoni (April 9, 2017). "'President Trump what the f**k are you doing' say Shadow Brokers and dump more NSA hacking tools". International Business Times UK. Retrieved April 10, 2017.
- "'NSA malware' released by Shadow Brokers hacker group". BBC News. April 10, 2017. Retrieved April 10, 2017.
- "Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN". ESET North America. Archived from the original on 16 May 2017. Retrieved 16 May 2017.
- Cimpanu, Catalin (13 May 2017). "Microsoft Releases Patch for Older Windows Versions to Protect Against Wana Decrypt0r". Bleeping Computer. Retrieved 13 May 2017.
- "Windows Vista Lifecycle Policy". Microsoft. Retrieved 13 May 2017.
- "Microsoft Security Bulletin MS17-010 – Critical". technet.microsoft.com. Retrieved 13 May 2017.
- Newman, Lily Hay. "The Ransomware Meltdown Experts Warned About Is Here". Wired.com. Retrieved 13 May 2017.
- "Wanna Decryptor: The NSA-derived ransomware worm shutting down computers worldwide". Ars Technica UK. Retrieved May 13, 2017.
- Surur (13 May 2017). "Microsoft release Wannacrypt patch for unsupported Windows XP, Windows 8 and Windows Server 2003". Retrieved 13 May 2017.
- MSRC Team. "Customer Guidance for WannaCrypt attacks". microsoft.com. Retrieved 13 May 2017.