cbcvebase.
CVE-2020-1301
published 2020-06-09

CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB…

PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
36.71%
98.3th percentile
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.

Affected

74 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10

Detection & IOCsextracted from sources · hover to see the quote

snort
Snort rules 54270 and 54271
  • CVE-2020-1301 (SMBLost) requires an authenticated attacker to send a specially crafted packet to an SMBv1 server — monitor for anomalous authenticated SMBv1 traffic, especially crafted request packets.
  • SMBLost (CVE-2020-1301) is post-authentication — correlate authenticated SMBv1 sessions followed by unusual server behavior (BSoD/crash) as a potential exploitation indicator.
  • Airbus published a PoC for SMBLost that results in denial of service via BSoD — unexpected system crashes on SMBv1 servers may indicate exploitation attempts.
  • CVE-2020-1301 primarily affects Windows 7 and Windows Server 2008 (end-of-life) systems running SMBv1 — prioritize detection on these legacy platforms.
  • ·Exploitation requires valid credentials (post-authentication) — unauthenticated exploitation is not possible, limiting the attack surface compared to EternalBlue/SMBGhost.
  • ·The Talos Snort rule set covers multiple June 2020 Patch Tuesday CVEs — not all listed rule IDs are exclusively for CVE-2020-1301; confirm rule-to-CVE mapping before deploying.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.