Skip to main content

Port Details

Port
445
Transport
TCP
Service
SMB
IANA service name
microsoft-ds
Range
System port (0-1023)
Related ports

Security Exposure

SMB exposed to the internet gives remote attackers a direct path to file shares, authentication and the SMB server code. CISA reported that WannaCry scanned IP ranges for TCP 445 and spread through the SMBv1 vulnerability fixed in MS17-010, and advised blocking SMB at the network boundary where the patch could not be applied. Microsoft also advises blocking outbound TCP 445 to the internet so internal devices cannot send data over SMB to outside hosts.

Hardening

  • +Block TCP 445 inbound and outbound at the internet edge; use SMB over QUIC or a VPN for remote file access.
  • +Remove SMBv1 from servers and clients; it is not installed by default on Windows Server 2019 and later.
  • +Require SMB signing so tampered messages fail signature checks.
  • +Use host firewall rules to limit SMB to the servers that actually need it, which reduces lateral movement.
  • +Apply Windows and Samba security updates promptly, including MS17-010 on any legacy system.

Monitoring

Enable File Share auditing under Advanced Audit Policy (Object Access) to see which hosts connect to which shares. Watch for SMB connections between workstations and for any 445 traffic crossing the internet edge.

SMB Vulnerabilities

11 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Microsoft8.882.7%KEV2025-06-10
CVE-2017-7494
Samba Remote Code Execution Vulnerability
Samba9.899.4%KEV2017-05-30
CVE-2017-0147
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Microsoft Corporation7.599.7%KEV2017-03-17
CVE-2019-0703
Microsoft Windows SMB Information Disclosure Vulnerability
Microsoft6.59.6%KEV2019-04-08
CVE-2017-0148
Microsoft SMBv1 Server Remote Code Execution Vulnerability
Microsoft Corporation8.199.4%KEV2017-03-17
CVE-2017-0146
Microsoft Windows SMB Remote Code Execution Vulnerability
Microsoft Corporation8.889.9%KEV2017-03-17
CVE-2020-0796
Microsoft SMBv3 Remote Code Execution Vulnerability
Microsoft10.099.8%KEV2020-03-12
CVE-2017-0144
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft Corporation8.899.2%KEV2017-03-17
CVE-2017-0145
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft Corporation8.889.8%KEV2017-03-17
CVE-2017-0143
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Corporation8.893.3%KEV2017-03-17
CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
Red Hat9.013.9%2026-05-26

Tools for Auditing and Monitoring SMB

Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

NetExec

Open Source
Penetration Testing Tools

Network service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.

LicenseBSD-2-Clause
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is port 445 TCP or UDP?→

IANA registers microsoft-ds on both, but SMB in practice uses TCP 445. Microsoft guidance refers to blocking TCP port 445.

Should port 445 be open to the internet?→

No. Microsoft recommends blocking TCP 445 inbound from the internet at corporate firewalls and offers SMB over QUIC on UDP 443 for remote file access.

What is the difference between port 139 and 445?→

Port 139 carries SMB over NetBIOS session service. Microsoft notes that shares made with SMB2 or later do not use NetBIOS ports 137 to 139.

Which vulnerabilities affect the service on port 445?→

This database lists 11 CVEs related to SMB, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-33073, CVE-2017-7494, CVE-2017-0147, CVE-2019-0703.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 445 is not guaranteed to be SMB. Exploited-in-the-wild data from the CISA KEV catalog (CC0).