The first priority is to apply Microsoft’s MS17-010 patch to any affected Windows system. If patching cannot be completed immediately, teams should disable SMBv1 and remove the system from direct internet exposure. Because EternalBlue is triggered by a crafted network message, reducing reachability and eliminating the vulnerable protocol are the fastest ways to cut exploitability.
What to do first when SMBv1 is still exposed on older Windows systems
The first move is to reduce exploitable reach as quickly as possible, then close the vulnerable gap. If an affected host can be patched immediately, apply MS17-010 right away. If not, disable SMBv1 and remove the system from direct internet exposure so the legacy protocol is not reachable while remediation is pending.
That order matters because EternalBlue is a network-reachable exploit, so exposure reduction can buy time even before full cleanup is complete.
Why patching and exposure reduction come before everything else
SMBv1 is dangerous here because the weakness is not theoretical, it is a remotely triggerable condition on systems that still accept legacy SMB traffic. Once the service is reachable, an attacker does not need credentials to begin exploitation, which is why teams should treat the issue as an exposure problem as much as a patching problem.
Applying the patch removes the known vulnerability, but on older systems patching can be delayed by maintenance windows, application compatibility, or change-control friction. In that situation, disabling SMBv1 and cutting off internet-facing reachability shrink the attack surface immediately, which is often the fastest practical risk reduction available.
When SMBv1 must remain enabled for a short transition period, the goal is to confine it to the smallest possible trust boundary. That means limiting which hosts can talk to it, avoiding exposure to untrusted networks, and treating any lingering SMBv1 dependency as temporary technical debt that needs a planned removal date.
How to sequence the response on legacy Windows hosts
Start with the systems that are both vulnerable and reachable, because exploitability is highest there. A host that is patched but still exposed is a weaker problem than an unpatched host on a routed or internet-facing segment, so remediation priority should reflect both vulnerability and connectivity.
On the operational side, the fastest safe sequence is usually:
- Patch affected systems with MS17-010 where feasible.
- Disable SMBv1 on hosts that cannot be patched immediately.
- Restrict network access so SMB traffic is limited to required internal sources.
- Plan replacement or upgrade for systems that still require SMBv1 to function.
That sequence keeps the focus on what changes the attack path most quickly. Removing reachability is not a substitute for patching, but it is often the difference between a controllable legacy exception and an open exploitation window.
Risk and Threat Considerations
Old Windows systems that still expose SMBv1 are attractive because the exploit path is simple, remotely reachable, and often usable at scale. If the host is internet-facing or broadly reachable inside the network, the risk is not just compromise of one system, but rapid propagation through flat or weakly segmented environments.
Failure mechanism: The vulnerable SMB service remains reachable long enough for a crafted network message to trigger code execution before patching or isolation is completed.
Impact: Attackers can gain unauthorised access, move laterally, and use the compromised host as a foothold for broader ransomware or intrusion activity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-2 — Flaw Remediation | MS17-010 patching is direct flaw remediation for a known Windows vulnerability. |
| SC-7 — Boundary Protection | Disabling SMBv1 and removing internet exposure are boundary protections that reduce reachability. | |
| CM-7 — Least Functionality | Disabling SMBv1 removes an unnecessary legacy protocol to reduce attack surface. | |
| Recommendation — Prioritise rapid remediation for affected hosts and verify patch deployment across the vulnerable estate. Restrict SMB reachability to approved segments and block exposure to untrusted networks. Disable unsupported legacy services and retain only the protocols required for business operation. | ||
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Hardening older Windows systems includes disabling vulnerable legacy services like SMBv1. |
| CIS-7 — Continuous Vulnerability Management | The first step is to identify and remediate systems still exposed to a known exploit. | |
| Recommendation — Apply hardened baseline settings and remove insecure legacy protocols from Windows systems. Track vulnerable hosts continuously and remediate them in priority order by exposure. | ||
| MITRE ATT&CK | T1210 — Exploitation of Remote Services | EternalBlue exploits a remotely reachable service, matching remote-service exploitation risk. |
| Recommendation — Hunt for reachable legacy services and treat them as likely initial-access paths. | ||
Practitioner Guidance
What to prioritise: Patch hosts that are both vulnerable and reachable first, because exposure plus known exploitation is the highest-risk combination. If a system cannot be patched quickly, treat network isolation as a temporary compensating control, not as a finish line.
What to verify: Confirm that SMBv1 is actually disabled at the host level and that the system is no longer reachable from untrusted networks on SMB ports. A policy change without reachability verification is not enough.
Practitioner takeaway: When SMBv1 exposure persists, the immediate objective is to collapse the exploit window, by patching where possible and by removing reachability where patching lags.
Related resources from NHI Mgmt Group
- How should security teams approach TLS migration when legacy systems still depend on older protocol assumptions?
- How should security teams reduce ransomware risk in factory environments that still depend on Windows systems and shared operational access?
- What should manufacturing security teams do first to reduce cyberattack exposure across plant and enterprise systems?
- How should security teams modernize encryption when legacy protocols are still embedded in older systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org