Microsoft SMBv3 Remote Code Execution Vulnerability
cve CVE-2020-0796 4 sources, 7 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-0796 the claim
Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-0796 the claim
What it is to other things
| affects | microsoft/windows_10_1903 NVD |
| affects | microsoft/windows_10_1909 NVD |
| affects | microsoft/windows_server_1903 NVD |
| affects | microsoft/windows_server_1909 NVD |
| made_by | microsoft NVD |
In words only, so not counted until a person confirms one:
| affects | microsoft/windows_10_version_1903_for_32_bit_systemsNVD says “Microsoft · Windows 10 Version 1903 for 32-bit Systems” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Daniel García Gutiérrezreceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "Daniel García Gutiérrez",
"codes": "CVE-2020-0796",
"date_added": "2020-03-30",
"date_published": "2020-03-30",
"date_updated": "2020-03-30",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation",
"file": "exploits/windows/local/48267.txt",
"id": "48267",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/danigargu/CVE-2020-0796/tree/02df8af47f8d47fd17edb03b69da8bf6272cc544",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Author author | chompie1337receipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "chompie1337",
"codes": "CVE-2020-0796",
"date_added": "2020-06-02",
"date_published": "2020-06-02",
"date_updated": "2020-06-02",
"description": "Microsoft Windows - 'SMBGhost' Remote Code Execution",
"file": "exploits/windows/remote/48537.py",
"id": "48537",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/chompie1337/SMBGhost_RCE_PoC/tree/92c9f46e46334c3bc3645ace3014622efd11704a",
"tags": "",
"type": "remote",
"verified": "0"
} | — | |
| Author author | eerykittyreceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "eerykitty",
"codes": "CVE-2020-0796",
"date_added": "2020-03-14",
"date_published": "2020-03-14",
"date_updated": "2020-03-14",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
"file": "exploits/windows/dos/48216.md",
"id": "48216",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/eerykitty/CVE-2020-0796-PoC/tree/5378663af950bbb24ef79d4a9050b0e008396caa",
"tags": "",
"type": "dos",
"verified": "0"
} | — | |
| Cvss cvss | NVD | 10receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Windows 10 Version 1903 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1903 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1909 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cisaActionDue": "2022-08-10",
"cisaExploitAdd": "2022-02-10",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9E1ED169-6F03-4BD5-B227-5FA54DB40AD7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "5C5B5180-1E12-45C2-8275-B9E528955307",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "B6A0DB01-49CB-4445-AFE8-57C2186857BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9285A9B5-4759-43E7-9589-CDBCA7100605",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "0D77EA14-F61D-4B9E-A385-70B88C482116",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "1A6FC9EE-D486-4AFE-A20E-4278468A1779",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "FFE3495D-291C-46B6-B758-23E16A53A7C3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "11E7F8F0-4FA8-4AA6-92A5-860E77AC933D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de ejecución de código remota en la manera en que el protocolo Microsoft Server Message Block (SMBv3) versión 3.1.1, maneja determinadas peticiones, también se conoce como ''Windows SMBv3 Client/Server Remote Code Execution Vulnerability\"."
}
],
"id": "CVE-2020-0796",
"lastModified": "2026-10-01T20:17:17.727",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-0796",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T03:55:42.606576Z",
"version": "2.0.3"
}
}
]
},
"published": "2020-03-12T16:15:15.627",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-119receipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2022-08-10receipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Knownreceipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | windowsreceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "eerykitty",
"codes": "CVE-2020-0796",
"date_added": "2020-03-14",
"date_published": "2020-03-14",
"date_updated": "2020-03-14",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
"file": "exploits/windows/dos/48216.md",
"id": "48216",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/eerykitty/CVE-2020-0796-PoC/tree/5378663af950bbb24ef79d4a9050b0e008396caa",
"tags": "",
"type": "dos",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | Windowsreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"Daniel García Gutiérrez",
"Manuel Blanco Parajón",
"Spencer McIntyre"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to\n execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself\n before injecting a payload into winlogon.exe.",
"disclosure_date": "2020-03-13",
"fullname": "exploit/windows/local/cve_2020_0796_smbghost",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:46 +0000",
"name": "SMBv3 Compression Buffer Overflow",
"needs_cleanup": null,
"notes": {
"AKA": [
"SMBGhost",
"CoronaBlue"
],
"RelatedModules": [
"exploit/windows/smb/cve_2020_0796_smbghost"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-os-restarts"
]
},
"path": "/modules/exploits/windows/local/cve_2020_0796_smbghost.rb",
"platform": "Windows",
"post_auth": false,
"rank": 400,
"ref_name": "windows/local/cve_2020_0796_smbghost",
"references": [
"CVE-2020-0796",
"URL-https://github.com/danigargu/CVE-2020-0796",
"URL-https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Windows 10 v1903-1909 x64"
],
"type": "exploit"
} | — |
| Product product not compared | CISA Known Exploited Vulnerabilities | SMBv3receipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Product product not compared | NVD | Windows 10 Version 1903 for 32-bit Systemsreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Windows 10 Version 1903 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1903 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1909 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cisaActionDue": "2022-08-10",
"cisaExploitAdd": "2022-02-10",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9E1ED169-6F03-4BD5-B227-5FA54DB40AD7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "5C5B5180-1E12-45C2-8275-B9E528955307",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "B6A0DB01-49CB-4445-AFE8-57C2186857BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9285A9B5-4759-43E7-9589-CDBCA7100605",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "0D77EA14-F61D-4B9E-A385-70B88C482116",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "1A6FC9EE-D486-4AFE-A20E-4278468A1779",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "FFE3495D-291C-46B6-B758-23E16A53A7C3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "11E7F8F0-4FA8-4AA6-92A5-860E77AC933D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de ejecución de código remota en la manera en que el protocolo Microsoft Server Message Block (SMBv3) versión 3.1.1, maneja determinadas peticiones, también se conoce como ''Windows SMBv3 Client/Server Remote Code Execution Vulnerability\"."
}
],
"id": "CVE-2020-0796",
"lastModified": "2026-10-01T20:17:17.727",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-0796",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T03:55:42.606576Z",
"version": "2.0.3"
}
}
]
},
"published": "2020-03-12T16:15:15.627",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Rank rank | Metasploit exploit modules | 200 Average. Works, unreliably or in specific conditions. receipt
What the source handed over{
"aliases": [],
"arch": "x64",
"author": [
"hugeh0ge",
"chompie1337",
"Spencer McIntyre"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to\n execute code on a vulnerable server. This remove exploit implementation leverages this flaw to execute code\n in the context of the kernel, finally yielding a session as NT AUTHORITY\\SYSTEM in spoolsv.exe. Exploitation\n can take a few minutes as the necessary data is gathered.",
"disclosure_date": "2020-03-13",
"fullname": "exploit/windows/smb/cve_2020_0796_smbghost",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:58 +0000",
"name": "SMBv3 Compression Buffer Overflow",
"needs_cleanup": null,
"notes": {
"AKA": [
"SMBGhost",
"CoronaBlue"
],
"RelatedModules": [
"exploit/windows/local/cve_2020_0796_smbghost"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [],
"Stability": [
"crash-os-restarts"
]
},
"path": "/modules/exploits/windows/smb/cve_2020_0796_smbghost.rb",
"platform": "Windows",
"post_auth": false,
"rank": 200,
"ref_name": "windows/smb/cve_2020_0796_smbghost",
"references": [
"CVE-2020-0796",
"URL-https://ricercasecurity.blogspot.com/2020/04/ill-ask-your-body-smbghost-pre-auth-rce.html",
"URL-https://github.com/chompie1337/SMBGhost_RCE_PoC",
"URL-https://www.youtube.com/watch?v=RSV3f6aEJFY&t=1865s",
"URL-https://www.coresecurity.com/core-labs/articles/getting-physical-extreme-abuse-of-intel-based-paging-systems",
"URL-https://www.coresecurity.com/core-labs/articles/getting-physical-extreme-abuse-of-intel-based-paging-systems-part-2-windows",
"URL-https://labs.bluefrostsecurity.de/blog/2017/05/11/windows-10-hals-heap-extinction-of-the-halpinterruptcontroller-table-exploitation-technique/"
],
"rport": 445,
"session_types": false,
"targets": [
"Windows 10 v1903-1909 x64"
],
"type": "exploit"
} | — |
| Rank rank | 400 Good. A default target, reliable against the common configuration. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"Daniel García Gutiérrez",
"Manuel Blanco Parajón",
"Spencer McIntyre"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to\n execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself\n before injecting a payload into winlogon.exe.",
"disclosure_date": "2020-03-13",
"fullname": "exploit/windows/local/cve_2020_0796_smbghost",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:46 +0000",
"name": "SMBv3 Compression Buffer Overflow",
"needs_cleanup": null,
"notes": {
"AKA": [
"SMBGhost",
"CoronaBlue"
],
"RelatedModules": [
"exploit/windows/smb/cve_2020_0796_smbghost"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-os-restarts"
]
},
"path": "/modules/exploits/windows/local/cve_2020_0796_smbghost.rb",
"platform": "Windows",
"post_auth": false,
"rank": 400,
"ref_name": "windows/local/cve_2020_0796_smbghost",
"references": [
"CVE-2020-0796",
"URL-https://github.com/danigargu/CVE-2020-0796",
"URL-https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Windows 10 v1903-1909 x64"
],
"type": "exploit"
} | — | |
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Windows 10 Version 1903 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1903 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1909 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cisaActionDue": "2022-08-10",
"cisaExploitAdd": "2022-02-10",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9E1ED169-6F03-4BD5-B227-5FA54DB40AD7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "5C5B5180-1E12-45C2-8275-B9E528955307",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "B6A0DB01-49CB-4445-AFE8-57C2186857BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9285A9B5-4759-43E7-9589-CDBCA7100605",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "0D77EA14-F61D-4B9E-A385-70B88C482116",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "1A6FC9EE-D486-4AFE-A20E-4278468A1779",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "FFE3495D-291C-46B6-B758-23E16A53A7C3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "11E7F8F0-4FA8-4AA6-92A5-860E77AC933D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de ejecución de código remota en la manera en que el protocolo Microsoft Server Message Block (SMBv3) versión 3.1.1, maneja determinadas peticiones, también se conoce como ''Windows SMBv3 Client/Server Remote Code Execution Vulnerability\"."
}
],
"id": "CVE-2020-0796",
"lastModified": "2026-10-01T20:17:17.727",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-0796",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T03:55:42.606576Z",
"version": "2.0.3"
}
}
]
},
"published": "2020-03-12T16:15:15.627",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Type type | Exploit-DB | dosreceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "eerykitty",
"codes": "CVE-2020-0796",
"date_added": "2020-03-14",
"date_published": "2020-03-14",
"date_updated": "2020-03-14",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
"file": "exploits/windows/dos/48216.md",
"id": "48216",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/eerykitty/CVE-2020-0796-PoC/tree/5378663af950bbb24ef79d4a9050b0e008396caa",
"tags": "",
"type": "dos",
"verified": "0"
} | — |
| Type type | localreceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "Daniel García Gutiérrez",
"codes": "CVE-2020-0796",
"date_added": "2020-03-30",
"date_published": "2020-03-30",
"date_updated": "2020-03-30",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation",
"file": "exploits/windows/local/48267.txt",
"id": "48267",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/danigargu/CVE-2020-0796/tree/02df8af47f8d47fd17edb03b69da8bf6272cc544",
"tags": "",
"type": "local",
"verified": "0"
} | — | |
| Type type | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "chompie1337",
"codes": "CVE-2020-0796",
"date_added": "2020-06-02",
"date_published": "2020-06-02",
"date_updated": "2020-06-02",
"description": "Microsoft Windows - 'SMBGhost' Remote Code Execution",
"file": "exploits/windows/remote/48537.py",
"id": "48537",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/chompie1337/SMBGhost_RCE_PoC/tree/92c9f46e46334c3bc3645ace3014622efd11704a",
"tags": "",
"type": "remote",
"verified": "0"
} | — | |
| Vendor vendor | NVD | Microsoftreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Windows 10 Version 1903 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1903 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1903 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for 32-bit Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for x64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows 10 Version 1909 for ARM64-based Systems",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
},
{
"product": "Windows Server, version 1909 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cisaActionDue": "2022-08-10",
"cisaExploitAdd": "2022-02-10",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9E1ED169-6F03-4BD5-B227-5FA54DB40AD7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "5C5B5180-1E12-45C2-8275-B9E528955307",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "B6A0DB01-49CB-4445-AFE8-57C2186857BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9285A9B5-4759-43E7-9589-CDBCA7100605",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "0D77EA14-F61D-4B9E-A385-70B88C482116",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:*",
"matchCriteriaId": "1A6FC9EE-D486-4AFE-A20E-4278468A1779",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "FFE3495D-291C-46B6-B758-23E16A53A7C3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:*",
"matchCriteriaId": "11E7F8F0-4FA8-4AA6-92A5-860E77AC933D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de ejecución de código remota en la manera en que el protocolo Microsoft Server Message Block (SMBv3) versión 3.1.1, maneja determinadas peticiones, también se conoce como ''Windows SMBv3 Client/Server Remote Code Execution Vulnerability\"."
}
],
"id": "CVE-2020-0796",
"lastModified": "2026-10-01T20:17:17.727",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 6.0,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-0796",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T03:55:42.606576Z",
"version": "2.0.3"
}
}
]
},
"published": "2020-03-12T16:15:15.627",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "secure@microsoft.com",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
],
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
},
{
"description": [
{
"lang": "en",
"value": "CWE-119"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Microsoftreceipt
What the source handed over{
"cveID": "CVE-2020-0796",
"cwes": "CWE-119",
"dateAdded": "2022-02-10",
"dueDate": "2022-08-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
"product": "SMBv3",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "SMBGhost",
"application_url": "",
"author": "eerykitty",
"codes": "CVE-2020-0796",
"date_added": "2020-03-14",
"date_published": "2020-03-14",
"date_updated": "2020-03-14",
"description": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
"file": "exploits/windows/dos/48216.md",
"id": "48216",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/eerykitty/CVE-2020-0796-PoC/tree/5378663af950bbb24ef79d4a9050b0e008396caa",
"tags": "",
"type": "dos",
"verified": "0"
} | — |
vulnerability
| Microsoft SMBv3 Remote Code Execution Vulnerability zetlyn/cve-kev · 2022-02-10 | cwes CWE-119 due_date 2022-08-10 exploited yes forensic_triage false known_ransomware_campaign_use Known product SMBv3 vendor_project Microsoft | |
| A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. zetlyn/cve-nvd · 2020-03-12 | cvss 10 product Windows 10 Version 1903 for 32-bit Systems status Analyzed vendor Microsoft | source |
exploit
| SMBv3 Compression Buffer Overflow zetlyn/cve-metasploit · 2020-03-13 | platform Windows rank 400 | source |
| SMBv3 Compression Buffer Overflow zetlyn/cve-metasploit · 2020-03-13 | platform Windows rank 200 | source |
| Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC) zetlyn/cve-exploitdb · 2020-03-14 | author eerykitty platform windows type dos verified false | source |
| Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation zetlyn/cve-exploitdb · 2020-03-30 | author Daniel García Gutiérrez platform windows type local verified false | source |
| Microsoft Windows - 'SMBGhost' Remote Code Execution zetlyn/cve-exploitdb · 2020-06-02 | author chompie1337 platform windows type remote verified false | source |