Port 139: NetBIOS Session Service (SMB over NetBIOS)
TCP port 139 is the NetBIOS Session Service (RFC 1002), which carries SMB file and printer sharing over NetBIOS. Modern Windows clients use SMB directly over TCP 445, and Microsoft describes the NetBIOS ports as optional because Windows 2000 and newer clients can work over port 445.
Port Details
Security Exposure
SMB reachable from untrusted networks is a target for remote code execution, data theft, lateral movement, and malware spread (UK Government Cyber Unit). UK guidance links ports 137 to 139 with SMBv1 and cites EternalBlue (CVE-2017-0144), which led to the WannaCry ransomware outbreak, as an example of attacks on open SMB ports. MITRE ATT&CK lists NetBIOS/SMB on 139/TCP among services targeted by password guessing.
Hardening
- +Block TCP 139 and 445 inbound from the internet at the perimeter firewall.
- +Disable SMBv1 and NetBIOS over TCP/IP where no legacy client requires them.
- +Keep Windows and Samba servers patched.
- +Allow SMB only from trusted networks, or over a VPN for remote users.
Monitoring
Alert on SMB sessions to port 139 from unexpected sources, on hosts that still negotiate SMBv1, and on repeated authentication failures across accounts.
NetBIOS-SSN Vulnerabilities
11 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-33073 | Windows SMB Client Elevation of Privilege Vulnerability | Microsoft | 8.8 | 82.7% | KEV | 2025-06-10 |
| CVE-2017-7494 | Samba Remote Code Execution Vulnerability | Samba | 9.8 | 99.4% | KEV | 2017-05-30 |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure Vulnerability | Microsoft Corporation | 7.5 | 99.7% | KEV | 2017-03-17 |
| CVE-2019-0703 | Microsoft Windows SMB Information Disclosure Vulnerability | Microsoft | 6.5 | 9.6% | KEV | 2019-04-08 |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution Vulnerability | Microsoft Corporation | 8.1 | 99.4% | KEV | 2017-03-17 |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.9% | KEV | 2017-03-17 |
| CVE-2020-0796 | Microsoft SMBv3 Remote Code Execution Vulnerability | Microsoft | 10.0 | 99.8% | KEV | 2020-03-12 |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 99.2% | KEV | 2017-03-17 |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.8% | KEV | 2017-03-17 |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 93.3% | KEV | 2017-03-17 |
| CVE-2026-4480 | Samba: samba: remote code execution in printing subsystem via unescaped job description | Red Hat | 9.0 | 13.9% | 2026-05-26 |
Tools for Auditing and Monitoring NetBIOS-SSN
NetExec
Open SourceNetwork service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is the difference between port 139 and port 445?→
Port 139 runs SMB over the NetBIOS Session Service, while port 445 runs SMB directly over TCP. Microsoft notes that Windows 2000 and newer clients can work over port 445 alone.
Is it safe to close port 139?→
On networks that use SMB2 or later, usually yes. Microsoft states that SMB2 and later shares do not use ports 137 to 139; only SMB1 legacy setups need them.
Which vulnerabilities affect the service on port 139?→
This database lists 11 CVEs related to NetBIOS-SSN, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-33073, CVE-2017-7494, CVE-2017-0147, CVE-2019-0703.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 139)
- RFC 1002: Protocol Standard for a NetBIOS Service on a TCP/UDP Transport: Detailed Specifications
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Learn: Secure SMB traffic in Windows Server
- Microsoft Learn: Detect, enable, and disable SMBv1, SMBv2, and SMBv3 in Windows
- UK Government Cyber Unit: Open port 445, Server Message Block (SMB)
- MITRE ATT&CK T1110.001: Brute Force, Password Guessing
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 139 is not guaranteed to be NetBIOS-SSN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).