Back to overview

CVE-2020-0796

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

Metadata

CVE ID
CVE-2020-0796
State
PUBLISHED
Assigner
microsoft
Reserved
2019-11-04 00:00 UTC
Published
2020-03-12 15:48 UTC
Last updated
2025-10-21 23:35 UTC
Primary CWE
CWE-119
CWE-119 Improper Restriction of Operations within the Bounds…
Vendor / Product
Microsoft / Windows 10 Version 1903 for 32-bit Systems
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Microsoft SMBv3 Remote Code Execution Vulnerability
Vendor
Microsoft
Product
SMBv3
Added to KEV
2022-02-10
Due date
2022-08-10
Ransomware
Known use
Required action
Apply updates per vendor instructions.
CISA description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
Affected products (8)
VendorProductPlatformVersions
Microsoft Windows 10 Version 1903 for 32-bit Systems unspecified
Microsoft Windows 10 Version 1903 for ARM64-based Systems unspecified
Microsoft Windows 10 Version 1903 for x64-based Systems unspecified
Microsoft Windows 10 Version 1909 for 32-bit Systems unspecified
Microsoft Windows 10 Version 1909 for ARM64-based Systems unspecified
Microsoft Windows 10 Version 1909 for x64-based Systems unspecified
Microsoft Windows Server, version 1903 (Server Core installation) unspecified
Microsoft Windows Server, version 1909 (Server Core installation) unspecified
Weakness (CWE)
CWESourceDescription
cna Remote Code Execution
CWE-119 adp CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview