Skip to main content

Port Details

Port
139
Transport
TCP
Service
NetBIOS-SSN
IANA service name
netbios-ssn
Range
System port (0-1023)
Related ports

Security Exposure

SMB reachable from untrusted networks is a target for remote code execution, data theft, lateral movement, and malware spread (UK Government Cyber Unit). UK guidance links ports 137 to 139 with SMBv1 and cites EternalBlue (CVE-2017-0144), which led to the WannaCry ransomware outbreak, as an example of attacks on open SMB ports. MITRE ATT&CK lists NetBIOS/SMB on 139/TCP among services targeted by password guessing.

Hardening

  • +Block TCP 139 and 445 inbound from the internet at the perimeter firewall.
  • +Disable SMBv1 and NetBIOS over TCP/IP where no legacy client requires them.
  • +Keep Windows and Samba servers patched.
  • +Allow SMB only from trusted networks, or over a VPN for remote users.

Monitoring

Alert on SMB sessions to port 139 from unexpected sources, on hosts that still negotiate SMBv1, and on repeated authentication failures across accounts.

NetBIOS-SSN Vulnerabilities

11 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Microsoft8.882.7%KEV2025-06-10
CVE-2017-7494
Samba Remote Code Execution Vulnerability
Samba9.899.4%KEV2017-05-30
CVE-2017-0147
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Microsoft Corporation7.599.7%KEV2017-03-17
CVE-2019-0703
Microsoft Windows SMB Information Disclosure Vulnerability
Microsoft6.59.6%KEV2019-04-08
CVE-2017-0148
Microsoft SMBv1 Server Remote Code Execution Vulnerability
Microsoft Corporation8.199.4%KEV2017-03-17
CVE-2017-0146
Microsoft Windows SMB Remote Code Execution Vulnerability
Microsoft Corporation8.889.9%KEV2017-03-17
CVE-2020-0796
Microsoft SMBv3 Remote Code Execution Vulnerability
Microsoft10.099.8%KEV2020-03-12
CVE-2017-0144
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft Corporation8.899.2%KEV2017-03-17
CVE-2017-0145
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft Corporation8.889.8%KEV2017-03-17
CVE-2017-0143
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Corporation8.893.3%KEV2017-03-17
CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
Red Hat9.013.9%2026-05-26

Tools for Auditing and Monitoring NetBIOS-SSN

NetExec

Open Source
Penetration Testing Tools

Network service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.

LicenseBSD-2-Clause
PlatformLinux, macOS, Windows
Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is the difference between port 139 and port 445?→

Port 139 runs SMB over the NetBIOS Session Service, while port 445 runs SMB directly over TCP. Microsoft notes that Windows 2000 and newer clients can work over port 445 alone.

Is it safe to close port 139?→

On networks that use SMB2 or later, usually yes. Microsoft states that SMB2 and later shares do not use ports 137 to 139; only SMB1 legacy setups need them.

Which vulnerabilities affect the service on port 139?→

This database lists 11 CVEs related to NetBIOS-SSN, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-33073, CVE-2017-7494, CVE-2017-0147, CVE-2019-0703.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 139 is not guaranteed to be NetBIOS-SSN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).