EternalBlue

lore

securityhacking

The NSA-developed SMB exploit leaked in 2017 that powered WannaCry and NotPetya.

Developed inside the NSA and leaked by the Shadow Brokers in April 2017, EternalBlue weaponized a flaw in SMBv1 that Microsoft had patched a month earlier as MS17-010; within weeks it was driving WannaCry, and soon after, NotPetya. It became the reference case in the debate over governments stockpiling vulnerabilities instead of disclosing them. The exploit's afterlife on unpatched networks lasted years beyond the headlines.

EternalBlue is an exploit for a flaw in Microsoft's SMB file-sharing protocol, developed by the NSA and kept as an offensive capability rather than reported to the vendor. In April 2017 it was published by the Shadow Brokers, and within weeks it was the engine of both WannaCry and NotPetya.

The sequence is the argument. An agency found a vulnerability in software running on a very large share of the world's computers, judged that keeping it was worth more than fixing it, lost control of it, and the resulting worms caused billions in damage to hospitals, shipping companies and manufacturers. Microsoft had patched it a month before the leak went public, having been warned, which is the only reason the damage was not far worse.

It is now the standard reference in the vulnerabilities equities debate: when a government discovers a flaw, does it disclose so everyone is protected, or retain it for intelligence use. The retention argument is real, since some capabilities have genuine value. The counterargument is EternalBlue, which demonstrated that a stockpiled exploit is a liability held on behalf of everyone who uses the software, and that stockpiles leak.

All glossary entries