Check Point Research detailed how the EternalBlue exploit achieves remote code execution against vulnerable Windows machines by abusing CVE-2017-0144 in Microsoft bulletin MS17-010 over SMBv1. The exploit, leaked by The Shadow Brokers in the "Lost in Translation" dump, targets Windows versions prior to Windows 8 and chains multiple flaws in srv.sys to gain kernel-level code execution.
The research identified three key bugs: a wrong-casting flaw in FEA conversion that causes a non-paged pool overflow, a transaction parsing flaw that creates the size confusion needed to trigger it, and a session setup flaw that enables controlled heap grooming. The paper showed how attackers can shape kernel memory, overwrite srvnet structures and an MDL, redirect writes into the executable HAL heap on older systems, and execute payloads such as DoublePulsar when a crafted srvnet connection closes, with packet-level attack flow illustrated in a successful Windows 7 exploitation trace.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point Research released a technical analysis detailing how EternalBlue achieves remote code execution through three core bugs in SMB processing and kernel heap grooming. The paper also documented packet-level exploitation flow and how the exploit can lead to payload execution such as DoublePulsar on vulnerable Windows systems.
The Shadow Brokers publicly leaked the EternalBlue exploit as part of their 'Lost in Translation' release. The leak exposed offensive tooling that targeted the Windows SMBv1 vulnerability later tracked as CVE-2017-0144.
Microsoft issued security bulletin MS17-010 to fix CVE-2017-0144, the SMBv1 flaw abused by EternalBlue. The vulnerability affected Windows versions prior to Windows 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.