The most famous of the NSA tools leaked by the Shadow Brokers hacking group was EnternalBlue, which created many dangerous malware, including WannaCry, Petya, and most recently, the WannaMine ransomware .
Now, Sean Dillion, a security researcher at RiskSense, has modified the source code of three other tools leaked by the NSA, called EnternalRomance, EternalChampion, and EnternalSynergy. He also previously ported the EternalBlue flaw to work on Windows 10.
Dillion released the source code to his GitHub repo, which includes a disclaimer stating that “the software was created solely for academic research and the development of effective defense techniques.” He will not use it to attack systems.
The modified leaks are intended to exploit vulnerabilities CVE-2017-0146 and CVE-2017-0143. An attacker could compromise the affected Windows system and perform remote code execution and remote control operations.
Almost every version of Windows, released since Windows 2000, is affected, including 32-bit and 64-bit variants of Windows Server, XP, 7, Vista, 8, etc.
The list also includes Microsoft's latest operating system, Windows 10, which is believed to be safe from the modified leaks and provides all updates and security fixes. However, the threat remains for older versions of Windows 10 that have not been secured with the patches released last March.
What would make it more problematic is the fact that Microsoft even dropped support for them, for example, the Anniversary Update (14393), which is among the affected versions.
Leaks could also create problems for businesses that are hesitant to keep their software up to date, mainly due to compatibility issues.
To learn more, you can visit Dillion's repo
