Port 445: Server Message Block over TCP
Port 445 carries SMB directly over TCP for Windows file sharing, printer sharing, named pipes and many domain services. File servers and domain controllers need inbound SMB to do their job. Samba provides the same protocol on Linux and Unix systems.
Port Details
Security Exposure
SMB exposed to the internet gives remote attackers a direct path to file shares, authentication and the SMB server code. CISA reported that WannaCry scanned IP ranges for TCP 445 and spread through the SMBv1 vulnerability fixed in MS17-010, and advised blocking SMB at the network boundary where the patch could not be applied. Microsoft also advises blocking outbound TCP 445 to the internet so internal devices cannot send data over SMB to outside hosts.
Hardening
- +Block TCP 445 inbound and outbound at the internet edge; use SMB over QUIC or a VPN for remote file access.
- +Remove SMBv1 from servers and clients; it is not installed by default on Windows Server 2019 and later.
- +Require SMB signing so tampered messages fail signature checks.
- +Use host firewall rules to limit SMB to the servers that actually need it, which reduces lateral movement.
- +Apply Windows and Samba security updates promptly, including MS17-010 on any legacy system.
Monitoring
Enable File Share auditing under Advanced Audit Policy (Object Access) to see which hosts connect to which shares. Watch for SMB connections between workstations and for any 445 traffic crossing the internet edge.
SMB Vulnerabilities
11 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-33073 | Windows SMB Client Elevation of Privilege Vulnerability | Microsoft | 8.8 | 82.7% | KEV | 2025-06-10 |
| CVE-2017-7494 | Samba Remote Code Execution Vulnerability | Samba | 9.8 | 99.4% | KEV | 2017-05-30 |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure Vulnerability | Microsoft Corporation | 7.5 | 99.7% | KEV | 2017-03-17 |
| CVE-2019-0703 | Microsoft Windows SMB Information Disclosure Vulnerability | Microsoft | 6.5 | 9.6% | KEV | 2019-04-08 |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution Vulnerability | Microsoft Corporation | 8.1 | 99.4% | KEV | 2017-03-17 |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.9% | KEV | 2017-03-17 |
| CVE-2020-0796 | Microsoft SMBv3 Remote Code Execution Vulnerability | Microsoft | 10.0 | 99.8% | KEV | 2020-03-12 |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 99.2% | KEV | 2017-03-17 |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.8% | KEV | 2017-03-17 |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 93.3% | KEV | 2017-03-17 |
| CVE-2026-4480 | Samba: samba: remote code execution in printing subsystem via unescaped job description | Red Hat | 9.0 | 13.9% | 2026-05-26 |
Tools for Auditing and Monitoring SMB
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
NetExec
Open SourceNetwork service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
Is port 445 TCP or UDP?→
IANA registers microsoft-ds on both, but SMB in practice uses TCP 445. Microsoft guidance refers to blocking TCP port 445.
Should port 445 be open to the internet?→
No. Microsoft recommends blocking TCP 445 inbound from the internet at corporate firewalls and offers SMB over QUIC on UDP 443 for remote file access.
What is the difference between port 139 and 445?→
Port 139 carries SMB over NetBIOS session service. Microsoft notes that shares made with SMB2 or later do not use NetBIOS ports 137 to 139.
Which vulnerabilities affect the service on port 445?→
This database lists 11 CVEs related to SMB, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-33073, CVE-2017-7494, CVE-2017-0147, CVE-2019-0703.
Sources
- IANA Service Name and Port Number Registry: port 445
- Microsoft Learn: Secure SMB traffic in Windows Server
- Microsoft Learn: Service overview and network port requirements for Windows
- CISA: Indicators Associated With WannaCry Ransomware
- Microsoft Learn: How to detect, enable and disable SMBv1, SMBv2, and SMBv3 in Windows
- Microsoft Learn: Overview of Server Message Block signing
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 445 is not guaranteed to be SMB. Exploited-in-the-wild data from the CISA KEV catalog (CC0).