⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-08-10.

CVE-2020-0796

CWE-119Buffer Overflow21 documents13 sources
Severity
10.0CRITICAL
EPSS
94.4%
top 0.02%
CISA KEV
KEVRansomware
Added 2022-02-10
Due 2022-08-10
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMar 12
KEV addedFeb 10
Latest updateMay 24
KEV dueAug 10
CISA Required Action: Apply updates per vendor instructions.

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vh23-87v3-h8c6: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 32022-05-24
CVEList
CVE-2020-0796: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 32020-03-12
VulnCheck
Microsoft SMBv3 Remote Code Execution Vulnerability2020

💥Exploits & PoCs

4
Exploit-DB
Microsoft Windows - 'SMBGhost' Remote Code Execution2020-06-02
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation2020-03-30
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)2020-03-14
Nuclei
Microsoft SMBv3 - Remote Code Execution

📋Vendor Advisories

2
CISA
Microsoft SMBv3 Remote Code Execution Vulnerability2022-02-10
Microsoft
Windows SMBv3 Client/Server Remote Code Execution Vulnerability2020-03-10

🕵️Threat Intelligence

10
Qualys
Automatically Discover, Prioritize and Remediate Microsoft SMBv3 RCE Vulnerability (CVE-2020-0796) using Qualys VMDR | Qualys2020-03-16
Qualys
Automatically Discover, Prioritize and Remediate Microsoft SMBv3 RCE Vulnerability (CVE-2020-0796) using Qualys VMDR2020-03-16
Tenable
Media Alert: Tenable Releases Plugins for EternalDarkness2020-03-13
Fortinet
CVE-2020-0796 Memory Corruption Vulnerability in Windows 10 SMB Server | FortiGuard Labs2020-03-12
Qualys
Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)2020-03-11
CVE-2020-0796 (CRITICAL CVSS 10) | A remote code execution vulnerabili | cvebase.io