{"id":4146,"date":"2025-03-14T20:46:05","date_gmt":"2025-03-15T04:46:05","guid":{"rendered":"https:\/\/www.antivirusaz.com\/faq\/?post_type=ht_kb&#038;p=4146"},"modified":"2025-04-07T10:50:49","modified_gmt":"2025-04-07T18:50:49","slug":"what-is-eternalblue-exploit","status":"publish","type":"ht_kb","link":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/","title":{"rendered":"What is EternalBlue exploit?"},"content":{"rendered":"<p><strong>EternalBlue<\/strong> is a software exploit that targets a vulnerability in Microsoft\u2019s Server Message Block (SMB) protocol. It allows an attacker to remotely execute code on unpatched Windows systems. EternalBlue was developed by the U.S. National Security Agency (NSA) and leaked by a hacking group known as the Shadow Brokers in 2017.<\/p>\n<p><strong>How does EternalBlue work?<\/strong><br \/>\nEternalBlue exploits a flaw in SMBv1. When a vulnerable system receives specially crafted packets, it allows remote attackers to execute arbitrary code. This can lead to full system compromise without user interaction.<\/p>\n<p><strong>Which systems are vulnerable to EternalBlue?<\/strong><br \/>\nWindows operating systems that had SMBv1 enabled and were not patched against the <a href=\"https:\/\/learn.microsoft.com\/en-us\/security-updates\/securitybulletins\/2017\/ms17-010\" target=\"_blank\" rel=\"noopener\">MS17-010 vulnerability<\/a> are susceptible. This includes versions from Windows XP to Windows Server 2012.<\/p>\n<p><strong>Why is EternalBlue significant?<\/strong><br \/>\nEternalBlue became widely known after it was used in major <a href=\"\/faq\/art\/what-is-ransomware\/\">ransomware<\/a> and malware attacks, such as <a href=\"\/security-center\/virus-information\/wannacry-ransomware.html\">WannaCry<\/a> and <a href=\"\/security-center\/virus-information\/notpetya.html\">NotPetya<\/a>. These attacks caused massive global damage by spreading rapidly and encrypting or destroying data.<\/p>\n<p><strong>What was the impact of attacks using EternalBlue?<\/strong><br \/>\nWannaCry infected over 200,000 computers in 150 countries, disrupting hospitals, businesses, and government systems. NotPetya caused billions in damages, particularly in Ukraine and among multinational companies.<\/p>\n<p><strong>How can EternalBlue be prevented?<\/strong><\/p>\n<ul>\n<li>Apply Microsoft\u2019s MS17-010 patch, released in March 2017.<\/li>\n<li>Disable SMBv1 where it\u2019s not needed.<\/li>\n<li>Use firewalls to block SMB traffic (ports 445 and 139) from untrusted networks.<\/li>\n<li>Regularly update and patch systems.<\/li>\n<\/ul>\n<p><strong>Is EternalBlue still a threat today?<\/strong><br \/>\nYes. Many unpatched or legacy systems still exist, especially in industries slow to update infrastructure. Attackers continue to exploit EternalBlue in modern malware campaigns.<\/p>\n<p><strong>Why didn\u2019t everyone patch their systems?<\/strong><br \/>\nMany organizations rely on legacy systems that can\u2019t be easily updated or replaced. Others delay patching due to operational disruptions or lack of awareness.<\/p>\n<p><strong>What lessons were learned from EternalBlue?<\/strong><\/p>\n<ul>\n<li>Timely patching is critical for security.<\/li>\n<li>Legacy protocols like SMBv1 should be phased out.<\/li>\n<li>Threats from leaked government exploits can have widespread consequences.<\/li>\n<li>Cyber hygiene (updates, backups, network segmentation) is essential.<\/li>\n<\/ul>\n<p><strong>What\u2019s the current status of EternalBlue?<\/strong><br \/>\nWhile Microsoft patched the vulnerability, the exploit is still in use by attackers targeting unpatched systems. EternalBlue remains a classic example of how a single vulnerability can lead to large-scale cyberattacks.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>EternalBlue is a software exploit that targets a vulnerability in Microsoft\u2019s Server Message Block (SMB) protocol. It allows an attacker to remotely execute code on unpatched Windows systems. EternalBlue was developed by the U.S. National Security Agency (NSA) and leaked by a hacking group known as the Shadow Brokers in 2017. How does EternalBlue work? [&hellip;]<\/p>\n","protected":false},"author":1,"comment_status":"open","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[12],"ht-kb-tag":[480,481],"class_list":["post-4146","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-threats-vulnerabilities","ht_kb_tag-eternalblue","ht_kb_tag-exploits"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is EternalBlue exploit?<\/title>\n<meta name=\"description\" content=\"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is EternalBlue exploit?\" \/>\n<meta property=\"og:description\" content=\"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/\" \/>\n<meta property=\"og:site_name\" content=\"Antivirus and Security Software FAQs &amp; Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-07T18:50:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/art\\\/what-is-eternalblue-exploit\\\/\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/art\\\/what-is-eternalblue-exploit\\\/\",\"name\":\"What is EternalBlue exploit?\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#website\"},\"datePublished\":\"2025-03-15T04:46:05+00:00\",\"dateModified\":\"2025-04-07T18:50:49+00:00\",\"description\":\"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/art\\\/what-is-eternalblue-exploit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/art\\\/what-is-eternalblue-exploit\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/art\\\/what-is-eternalblue-exploit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is EternalBlue exploit?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#website\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\",\"name\":\"Antivirus and Security Software FAQs & Blog\",\"description\":\"Frequently asked questions about antivirus and security software, and other computer security related issues.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#organization\"},\"alternateName\":\"AntivirusAZ.com FAQs & Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#organization\",\"name\":\"AntiVirusAZ.com\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/antivirusaz-faq-blog-logo.png\",\"contentUrl\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/antivirusaz-faq-blog-logo.png\",\"width\":1536,\"height\":512,\"caption\":\"AntiVirusAZ.com\"},\"image\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is EternalBlue exploit?","description":"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/","og_locale":"en_US","og_type":"article","og_title":"What is EternalBlue exploit?","og_description":"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.","og_url":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/","og_site_name":"Antivirus and Security Software FAQs &amp; Blog","article_modified_time":"2025-04-07T18:50:49+00:00","og_image":[{"width":1536,"height":512,"url":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/","url":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/","name":"What is EternalBlue exploit?","isPartOf":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#website"},"datePublished":"2025-03-15T04:46:05+00:00","dateModified":"2025-04-07T18:50:49+00:00","description":"Learn what EternalBlue is, how it works, the risks it poses, and how to protect systems from this major Windows exploit used in cyberattacks.","breadcrumb":{"@id":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.antivirusaz.com\/faq\/art\/what-is-eternalblue-exploit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.antivirusaz.com\/faq\/"},{"@type":"ListItem","position":2,"name":"What is EternalBlue exploit?"}]},{"@type":"WebSite","@id":"https:\/\/www.antivirusaz.com\/faq\/#website","url":"https:\/\/www.antivirusaz.com\/faq\/","name":"Antivirus and Security Software FAQs & Blog","description":"Frequently asked questions about antivirus and security software, and other computer security related issues.","publisher":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#organization"},"alternateName":"AntivirusAZ.com FAQs & Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.antivirusaz.com\/faq\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.antivirusaz.com\/faq\/#organization","name":"AntiVirusAZ.com","url":"https:\/\/www.antivirusaz.com\/faq\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/logo\/image\/","url":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png","contentUrl":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png","width":1536,"height":512,"caption":"AntiVirusAZ.com"},"image":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb\/4146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/comments?post=4146"}],"version-history":[{"count":1,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb\/4146\/revisions"}],"predecessor-version":[{"id":4147,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb\/4146\/revisions\/4147"}],"wp:attachment":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/media?parent=4146"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb-category?post=4146"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/ht-kb-tag?post=4146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}