KEVIntel
10.0
CVSS
Critical

CVE-2020-0796

PUBLISHED

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Microsoft
Product
Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation)
Published
Mar 12, 2020
EPSS

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

windows cisa malware ransomware nuclei_scanner metasploit microsoft

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-02-10 00:00:00 UTC · Source

Used in malware

Recorded 2022-02-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 10, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

cve_2020_0796_smbghost

metasploit · Created Unknown

Metasploit module for CVE-2020-0796

cve_2020_0796_smbghost

metasploit · Created Unknown

Metasploit module for CVE-2020-0796

madanokr001/CVE-2020-0796

github · Created 2025-04-19 05:29:17 UTC · 1 stars

monjheta/CVE-2020-0796

github · Created 2025-02-26 04:14:32 UTC · 0 stars

Kaizzzo1/CVE-2020-0796

github · Created 2025-01-29 08:52:02 UTC · 1 stars

dungnm24/CVE-2020-0796

github · Created 2023-05-29 06:31:51 UTC · 6 stars

WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.

krizzz07/CVE-2020-0796

github · Created 2023-01-29 04:29:49 UTC · 0 stars

windows 10 SMB vulnerability

SEHandler/CVE-2020-0796

github · Created 2022-11-09 13:46:24 UTC · 1 stars

CVE-2020-0796

arzuozkan/CVE-2020-0796

github · Created 2022-06-07 17:16:16 UTC · 1 stars

CVE-2020-0796 explanation and researching vulnerability for term porject CENG325

orangmuda/CVE-2020-0796

github · Created 2021-10-09 04:52:55 UTC · 4 stars

Remote Code Execution POC for CVE-2020-0796

Anonimo501/SMBGhost_CVE-2020-0796_checker

github · Created 2021-09-04 15:07:15 UTC · 2 stars

MasterSploit/LPE---CVE-2020-0796

github · Created 2020-11-20 09:00:08 UTC · 2 stars

codewithpradhan/SMBGhost-CVE-2020-0796-

github · Created 2020-09-28 05:23:20 UTC · 2 stars

To crash Windows-10 easily

rsmudge/CVE-2020-0796-BOF

github · Created 2020-09-17 01:48:37 UTC · 70 stars

exp-sky/CVE-2020-0796

github · Created 2020-06-09 06:18:54 UTC · 3 stars

SMBv3 Ghost (CVE-2020-0796) Vulnerability

ysyyrps123/CVE-2020-0796

github · Created 2020-06-02 12:04:30 UTC · 0 stars

CVE-2020-0796

halsten/CVE-2020-0796

github · Created 2020-05-28 08:41:12 UTC · 0 stars

syadg123/CVE-2020-0796

github · Created 2020-04-22 09:10:15 UTC · 2 stars

thelostworldFree/CVE-2020-0796

github · Created 2020-04-22 09:09:02 UTC · 11 stars

PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)

jamf/CVE-2020-0796-RCE-POC

github · Created 2020-04-20 14:35:48 UTC · 553 stars

CVE-2020-0796 Remote Code Execution POC

LabDookhtegan/CVE-2020-0796-EXP

github · Created 2020-04-02 15:32:10 UTC · 1 stars

CVE-2020-0796-EXP

eastmountyxz/CVE-2020-0796-SMB

github · Created 2020-04-02 12:12:03 UTC · 33 stars

该资源为CVE-2020-0796漏洞复现,包括Python版本和C++版本。主要是集合了github大神们的资源,希望您喜欢~

jiansiting/CVE-2020-0796

github · Created 2020-04-01 01:46:08 UTC · 62 stars

tango-j/CVE-2020-0796

github · Created 2020-03-31 19:01:52 UTC · 4 stars

Coronablue exploit

f1tz/CVE-2020-0796-LPE-EXP

github · Created 2020-03-31 11:25:50 UTC · 17 stars

Windows SMBv3 LPE exploit 已编译版

TinToSer/CVE-2020-0796-LPE

github · Created 2020-03-31 05:41:30 UTC · 2 stars

SMBGHOST local privilege escalation

jamf/CVE-2020-0796-LPE-POC

github · Created 2020-03-30 16:06:50 UTC · 241 stars

CVE-2020-0796 Local Privilege Escalation POC

danigargu/CVE-2020-0796

github · Created 2020-03-30 11:42:56 UTC · 1318 stars

CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost

cory-zajicek/CVE-2020-0796-DoS

github · Created 2020-03-21 18:17:10 UTC · 1 stars

DoS PoC for CVE-2020-0796 (SMBGhost)

julixsalas/CVE-2020-0796

github · Created 2020-03-16 15:39:22 UTC · 1 stars

Scanner for CVE-2020-0796

ran-sama/CVE-2020-0796

github · Created 2020-03-16 00:47:41 UTC · 1 stars

Lightweight PoC and Scanner for CVE-2020-0796 without authentication.

maxpl0it/Unauthenticated-CVE-2020-0796-PoC

github · Created 2020-03-15 22:17:50 UTC · 21 stars

An unauthenticated PoC for CVE-2020-0796

jiansiting/CVE-2020-0796-Scanner

github · Created 2020-03-15 03:17:47 UTC · 9 stars

CVE-2020-0796-Scanner

GuoKerS/aioScan_CVE-2020-0796

github · Created 2020-03-14 23:39:25 UTC · 16 stars

基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。

wsfengfan/CVE-2020-0796

github · Created 2020-03-14 05:39:37 UTC · 0 stars

CVE-2020-0796 Python POC buffer overflow

vysecurity/CVE-2020-0796

github · Created 2020-03-13 08:34:31 UTC · 5 stars

CVE-2020-0796 - Working PoC - 20200313

laolisafe/CVE-2020-0796

github · Created 2020-03-12 19:46:25 UTC · 2 stars

SMBv3 RCE vulnerability in SMBv3

eerykitty/CVE-2020-0796-PoC

github · Created 2020-03-12 18:34:40 UTC · 327 stars

PoC for triggering buffer overflow via CVE-2020-0796

xax007/CVE-2020-0796-Scanner

github · Created 2020-03-12 15:36:43 UTC · 0 stars

CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner

kn6869610/CVE-2020-0796

github · Created 2020-03-12 02:47:49 UTC · 0 stars

joaozietolie/CVE-2020-0796-Checker

github · Created 2020-03-11 16:23:03 UTC · 14 stars

Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)

T13nn3s/CVE-2020-0796

github · Created 2020-03-11 09:13:48 UTC · 28 stars

Powershell SMBv3 Compression checker

0x25bit/CVE-2020-0796-PoC

github · Created 2020-03-10 21:40:57 UTC · 19 stars

Weaponized PoC for SMBv3 TCP codec/compression vulnerability

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit

  • Detected by Nuclei