CVE-2020-1284Improper Validation of Specified Quantity in Input in Microsoft Windows 10 Version 2004 FOR 32-bit Systems

Severity
6.5MEDIUMNVD
EPSS
16.0%
top 5.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qjv9-w8r4-f5vx: A denial of service vulnerability exists in the way that the Microsoft Server Message Block 32022-05-24
GHSA
Improper Validation of Specified Quantity in Input in Eclipse Hono2022-02-10

📋Vendor Advisories

1
Microsoft
Windows SMBv3 Client/Server Denial of Service Vulnerability2020-06-09

🕵️Threat Intelligence

3
Trendmicro
Patch Tuesday: Fixes for LNK, SMB, and SharePoint Bugs2020-06-10
Tenable
Microsoft’s June 2020 Patch Tuesday Addresses 129 CVEs Including Newly Disclosed SMBv3 Vulnerability (CVE-2020-1206)2020-06-09
Zscaler
Zscaler found New Security Vulnerabilities | 10-06-2020