Let me post a documented answer to respond the question (or at least mostly).
It is informed in the Microsoft Security detailed report that for those legacy systems without updated Windows Defender, neither the updated patch kb4012598 has been applied yet, there are only two workarounds:
- Disable SMBv1 ...
- Block incoming SMB traffic on port 445 ...
I believe the above answer from MS should answer your question.