The United States Computer Emergency Readiness Team (US-CERT) is warning in a statement about a new exploit kit developed by the hacking group Shadow Brokers. The new exploit kit is available for sale and targets Windows systems.
Earlier this week, rumors circulated that the Shadow Brokers were trying to sell a Windows zero-day for 750 Bitcoin, and US-CERT says action should be taken immediately. 
In its publication, US-CERT says that the zero-day exploit targets a vulnerability that is available to all Windows systems through the Server Message Block (SMB) feature. A successful attack could allow an attacker to obtain sensitive information from affected systems.
The group recommends that Windows administrators disable SMB v1 and block all versions of SMB at the network boundary by blocking TCP port 445 along with all related protocols on UDP ports 137-138 and TCP port 139, for all devices, even though the above measures could obviously have an impact on the proper functioning of the system.
For now, however, it is important to note that there is still no confirmation of this particular zero-day in Windows, from Microsoft itself, which seems to be unaware that there is an unpatched vulnerability.
