RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Vulnerability

Vulnerability / From the archive · 14 March 2017 event · prepared 16 September 2026

Microsoft patched the SMB flaw two months before WannaCry hit

Microsoft's own bulletin and blog posts show the fix, the leak, and the warning all preceded the WannaCry worm.

learn.microsoft.comprimary record

Microsoft Security Bulletin MS17-010 - Critical

Document
14 March 2017
Event
14 March 2017
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

What happened

On 14 March 2017, Microsoft published security bulletin MS17-010, rated critical, fixing several remote code-execution and information-disclosure vulnerabilities in how the Windows SMBv1 file-sharing server handled specially crafted requests. A month later, a group calling itself the Shadow Brokers published a large set of exploit tools; Microsoft's own risk-evaluation post states that the company investigated the leak and found that four of the leaked tools, including one later known as EternalBlue, exploited vulnerabilities already patched by MS17-010, and that supported systems kept current with updates were not at risk from them.

Despite the March patch and April warning, the WannaCrypt worm used the same EternalBlue exploit to spread rapidly on 12 May 2017. Microsoft's customer guidance post, published the following day, describes its response as a highly unusual step: Microsoft issued emergency security updates for Windows XP, Windows 8 and Windows Server 2003, systems that were out of mainstream support and had not received MS17-010, because those customers had no other route to a fix.

Confidence and limits

All three documents come directly from Microsoft, describing its own bulletin, its own risk assessment of a public leak, and its own emergency response, so they are strong evidence of the timeline and of Microsoft's own actions. They are Microsoft's account of its own product security process rather than an independent forensic reconstruction of how WannaCrypt specifically entered each affected network, and this article does not estimate a global infection count or cost, since neither source states one.

Why it mattered

The sequence is unusually clean as a patch-management case study: a fix existed two months before the exploit leaked publicly, and Microsoft itself confirmed the leaked tool was already covered a full month before the worm appeared. The vulnerability, in the sense of a defect with no available remedy, effectively closed in March; what remained open on unpatched machines by May was a gap in deployment, not a gap in available protection. That distinction, between a flaw and the delay in fixing it, is why MS17-010 is frequently cited in discussions of patch prioritisation and of why unsupported legacy systems carry ongoing organisational risk beyond their own operation.

Defensive takeaway

Treat a critical bulletin covering a widely used protocol like SMB as time-sensitive from the day it is published, not from the day an exploit becomes public, and maintain an inventory of any systems still running end-of-support Windows versions so they can be prioritised or isolated ahead of the next equivalent bulletin.

  • How long, on average, does it take your organisation to deploy a critical Microsoft bulletin across all affected systems?
  • Do you know exactly which of your systems, if any, are still running Windows versions that no longer receive standard security updates?
  • Is SMBv1 disabled anywhere it is not specifically required, regardless of whether those systems are otherwise patched?

MS17-010 is remembered because of WannaCrypt, but the more useful reading keeps the two events separate: the vulnerability was fixed in March, the exploit's danger was confirmed and communicated in April, and the worm in May only reached machines where that two-month window had not been used.

Defensive takeaway

Treat a critical bulletin covering a widely used protocol like SMB as time-sensitive from the day it is published, not from the day an exploit becomes public, and maintain an inventory of any systems still running end-of-support Windows versions.

All three sources are Microsoft's own account of its bulletin, its risk assessment of the Shadow Brokers leak, and its emergency response, which is strong evidence of the timeline but not an independent forensic count of how the WannaCrypt worm entered each affected network.

Sources & reading trail

Microsoft Security Bulletin MS17-010 - Critical ↗

Confirms the 14 March 2017 publication date, the critical severity rating, and the SMBv1 vulnerabilities the update addressed.

vendor-primary · Source published: 14 March 2017 · Retrieved: 16 September 2026

Protecting customers and evaluating risk ↗

Confirms Microsoft's assessment that four Shadow Brokers-leaked exploits, including EternalBlue, were already patched by MS17-010.

vendor-primary · Source published: 15 April 2017 · Retrieved: 16 September 2026

Customer Guidance for WannaCrypt attacks ↗

Describes the WannaCrypt attack's use of the same exploit and records Microsoft's emergency patches for out-of-support Windows versions.

vendor-primary · Source published: 13 May 2017 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.