CVE-2020-0796
Microsoft SMBv3 Remote Code Execution Vulnerability
CVSS
10.0
Critical
EPSS
99.8%
p100
KEV
YES
Feb 10, 2022
Exploit Today
80
0-100
Published: Mar 12, 2020 · Last modified: Aug 12, 2026 · CWE-119
Product
Microsoft / SMBv3
Vulnerability
Microsoft SMBv3 Remote Code Execution Vulnerability
Added to KEV
Feb 10, 2022
Remediate by
Aug 10, 2022
Known ransomware use
Yes
Summary description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796