CVE-2020-17140
published 2020-12-09CVE-2020-17140: Windows SMB Information Disclosure Vulnerability Windows SMB Information Disclosure Vulnerability
medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
12.16%
95.7th percentile
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24563 | 6.1.7601.24563 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.24563 | 6.1.7601.24563 |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.24563 | 6.1.7601.24563 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < publication | publication |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
cvelistv58.1HIGH
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows SMB Information Disclosure Vulnerability
vendor_msrc·2020-12-08·CVSS 8.1
CVE-2020-17140 [HIGH] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
FAQ: Does this security update target the Server or Client side?
In this case the fix targets both sides. Specifically the smb2.srv binary is the primary fix target, which is housed on both sides of the connection.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of Kernel memory. An attacker could read the contents of Kernel memory from a user mode process.
FAQ: How could an attacker exploit this vulnerability?
In a network-based attack, an authenticated attacker would need to open a specific file with captured oplock lease, then perform repeated specific modifications to that file.
Windows SMB:
GHSA
GHSA-q4cp-ggx3-v3j7: , aka 'Windows SMB Information Disclosure Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-17140 [MEDIUM] CWE-200 GHSA-q4cp-ggx3-v3j7: , aka 'Windows SMB Information Disclosure Vulnerability'
, aka 'Windows SMB Information Disclosure Vulnerability'.
CVEList
Windows SMB Information Disclosure Vulnerability
cvelistv5·2020-12-09·CVSS 8.1
CVE-2020-17140 [HIGH] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
Checkpoint
14th December – Threat Intelligence Bulletin
blogs_checkpoint·2020-12-14
CVE-2020-1971 14th December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 14th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The US Treasury Department and US Department of Commerce were victims of a cyberattack compromising their internal email traffic. Perhaps related , SolarWinds IT management software has been exploited in a supply chain attack, adding malicious code to its software updates released between March and June 2020.
Habana
Trendmicro
December Patch Tuesday Fixes Exchange, SMB
blogs_trendmicro·2020-12-09·CVSS 6.6
[MEDIUM] December Patch Tuesday Fixes Exchange, SMB
# December Patch Tuesday Fixes Exchange, SMB
The last set of updates for the year includes 58 patches for the Microsoft Office suite.
By: Trend Micro
2020/12/09
Read time: ( words)
Save to Folio
Updated on 12/9/2020 02:37PM PST to include Trend Micro Deep Security and Vulnerability Protection rules.
The last set of updates for the year includes 58 patches for the Microsoft Office suite. Of the total number, nine have been rated Critical and 46 as Important. A significant number of updates fixes gaps in MS Exchange vulnerable to remote code execution (RCE) and information disclosure, as well as a server message block (SMB) gap also noted for the latter vulnerability. No zero days have been observed, though several vulnerabilities have been deemed as likely for abuse. Six of the total
2020-12-09
Published