Beyond the share-level attacks, the SMB server protocol has produced pre-authentication remote code execution. The SMBv1 EternalBlue family (MS17-010) corrupts the server's handling of crafted packets, and the SMBv3 compression flaw (SMBGhost) affects a specific Windows 10 and Server version range. Both yield SYSTEM on the file server from an unauthenticated network position.
Protocol-level SMB RCE:
- SMBv1 EternalBlue family (MS17-010): crafted-packet memory corruption
- SMBv3 compression (SMBGhost): integer handling in LZ77 decompression
Exploitation notes#
- These are SMB-server exploits, reachable wherever the file-sharing port is exposed, independent of any share permission.
- They are heavily covered as network exploitation; this page places them in the file-share context and cross-references the deeper treatment in the Network area.
- Fingerprint the SMB dialect and patch level (
nxc smb <t>, the server's build) before selecting a technique.