CVE detail
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
37 source links · newest first
- Researchers unearth keyloggers on Outlook login pagesHelp Net Security
Unknown threat actors have compromised internet-accessible Microsoft Exchange Servers of government organizations and companies around the world, and have injected the organizations’ Outlook on the Web (OWA) login page with browser-based keyloggers, Positive Technologies researchers have warned. The keylogging JavaScript code (Source: Positive Technologies) The initial vector for compromise is unknown The researchers haven’t been able to pinpoint how the attackers gained access to the compromised servers. Some of them were vulnerable to a slew … More →
newswww.helpnetsecurity.comJun 17, 2025, 3:35 PM BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses. Read our technical analysis.
vendorunit42.paloaltonetworks.comAug 10, 2022, 7:00 PM- Lemon_Duck cryptomining botnet targets Docker serversSecurity Affairs
The Lemon_Duck cryptomining botnet is targeting Docker servers to mine cryptocurrency on Linux systems. Crowdstrikes researchers reported that the Lemon_Duck cryptomining botnet is targeting Docker to mine cryptocurrency on Linux systems. The Lemon_Duck cryptomining malware was first spotted in June 2019 by researchers from Trend Micro while targeting enterprise networks. At the time of its first discovery, the bot was […]
newssecurityaffairs.comApr 22, 2022, 7:26 AM - CISA added 9 new flaws to the Known Exploited Vulnerabilities Catalog, including Magento e Chrome bugsSecurity Affairs
The U.S. CISA added to the Known Exploited Vulnerabilities Catalog another 9 security flaws actively exploited in the wild. US Cybersecurity and Infrastructure Security Agency (CISA) added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including two recently patched zero-day issues affecting Adobe Commerce/Magento Open Source and Google Chrome. CISA orders all Federal Civilian Executive […]
newssecurityaffairs.comFeb 16, 2022, 10:04 AM The U.S. CISA has added to the catalog of vulnerabilities another 15 security vulnerabilities actively exploited in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added fifteen more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that threat actors have abused in attacks […]
newssecurityaffairs.comFeb 11, 2022, 9:43 PMThe US Cybersecurity and Infrastructure Security Agency (CISA) has added 15 more vulnerabilities to its catalog of flaws that are actively exploited in the wild by hackers. Some are older dating back to 2014, but two are from the past two years and are in Windows components. “These types of vulnerabilities are a frequent attack […]
newswww.csoonline.comFeb 11, 2022, 8:16 PMNetwork attack trends in the Winter quarter of 2020 revealed some interesting trends, such as increased attacker preference for newly released vulnerabilities and a large uptick in attacks deemed Critical. In addition to details of the newly observed exploits, in this blog, we also dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
vendorunit42.paloaltonetworks.comApr 12, 2021, 5:37 PM- Top 10 most exploited vulnerabilities from 2020Help Net Security
Vulnerability intelligence-as-a-service outfit vFeed has compiled a list of the top 10 most exploited vulnerabilities from 2020, and among them are SMBGhost, Zerologon, and SIGRed. What is vFeed? vFeed analyzes a variety of vendor advisories and third-party sources, correlates the gathered info, and compiles and constantly updates a vulnerability and threat intelligence database/feed that SOC and security teams can use to prioritize the remediation of security issues. In most cases, securing and protecting companies networks … More →
newswww.helpnetsecurity.comFeb 3, 2021, 9:51 AM A Chinese Threat actor targeted organizations in Russia and Hong Kong with a previously undocumented backdoor, experts warn. Cybersecurity researchers from Positive Technologies have uncovered a series of attacks conducted by a Chinese threat actor that aimed at organizations in Russia and Hong Kong. Experts attribute the attacks to the China-linked Winnti APT group (aka APT41) […]
newssecurityaffairs.comJan 15, 2021, 2:13 PMOver 100,000 computers remain affected by the Windows vulnerability known as SMBGhost, more than half a year after a patch was rolled out, new research reveals.
newswww.securityweek.comNov 2, 2020, 6:43 PM- 2nd November – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 2nd November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches CISA, FBI and HHS have released a warning against an increase in Ryuk ransomware attacks on US hospitals. Check Point Research have shown that indeed, healthcare is currently the most targeted industry in […]
vendorresearch.checkpoint.comNov 2, 2020, 12:05 PM - 103,000 machines are still vulnerable to SMBGhost attacksSecurity Affairs
Eight months after Microsoft issued a patch for the critical SMBGhost issues over 100,000 systems exposed online are still vulnerable to this attack. In March, Microsoft has addressed the critical SMBGhost vulnerability (CVE-2020-0796) in the Server Message Block (SMB) protocol. “A remote code execution vulnerability exists in the way that the Microsoft Server Message Block […]
newssecurityaffairs.comNov 1, 2020, 9:29 AM - Lemon_Duck cryptomining malware evolves to target Linux devicesSecurity Affairs
A new variant of the infamous Lemon_Duck cryptomining malware has been updated to targets Linux devices. Security researchers from Sophos have spotted a new variant of the Lemon_Duck cryptomining malware that has been updated to compromise Linux machines via SSH brute force attacks. The new variant also exploits SMBGhost bug in Windows systems, and is also able to target servers running Redis […]
newssecurityaffairs.comAug 28, 2020, 9:06 AM Here’s an overview of some of last week’s most interesting news, articles and podcasts: Organizations are creating the perfect storm by not implementing security basics European organizations have a false sense of security when it comes to protecting themselves, with only 68% seeing themselves as vulnerable, down from 86% in 2018, according to Thales. 5 keys to protecting OneDrive users With the dramatic shift toward remote workforces over the last three months, many organizations are … More →
newswww.helpnetsecurity.comJun 14, 2020, 1:45 PM- SMBleed could allow a remote attacker to leak kernel memorySecurity Affairs
Microsoft addressed a Server Message Block (SMB) protocol issue, named SMBleed, that could allow an attacker to leak kernel memory remotely, without authentication. Recently released Microsoft June 2020 Patch Tuesday updates also address a vulnerability in the Server Message Block (SMB) protocol dubbed SMBleed (CVE-2020-1206) that could allow an attacker to leak kernel memory remotely, without […]
newssecurityaffairs.comJun 11, 2020, 9:38 AM One of the vulnerabilities that Microsoft addressed on June 2020 Patch Tuesday is a Server Message Block (SMB) protocol bug that could allow an attacker to leak kernel memory remotely, without authentication.
newswww.securityweek.comJun 10, 2020, 5:46 PMMicrosoft June 2020 Patch Tuesday address 129 vulnerabilities, 11 flaws are rated as Critical while 118 are rated as Important in severity. Microsoft June 2020 Patch Tuesday address 129 vulnerabilities affecting Microsoft Windows, Internet Explorer (IE), Microsoft Edge (EdgeHTML-based and Chromium-based in IE Mode), ChakraCore, Office and Microsoft Office Services and Web Apps, Windows Defender, […]
newssecurityaffairs.comJun 10, 2020, 8:04 AMMicrosoft’s security updates for June 2020 patch 129 vulnerabilities, including 11 critical remote code execution flaws affecting Windows, the Edge and Internet Explorer browsers, and SharePoint.
newswww.securityweek.comJun 10, 2020, 3:32 AM- PoC RCE exploit for SMBGhost Windows flaw releasedHelp Net Security
A security researcher has published a PoC RCE exploit for SMBGhost (CVE-2020-0796), a wormable flaw that affects SMBv3 on Windows 10 and some Windows Server versions. The PoC exploit is unreliable, but could be used by malicious attackers as a starting point for creating a more effective exploit. About SMBGhost (CVE-2020-0796) The existence of the flaw was inadvertently revealed in early March 2020 and Microsoft released patches soon after. The vulnerability could be exploited to … More →
newswww.helpnetsecurity.comJun 8, 2020, 10:05 AM The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has warned Windows users that a recently released proof-of-concept (PoC) exploit for the vulnerability tracked as SMBGhost has been abused to launch attacks.
newswww.securityweek.comJun 8, 2020, 7:54 AMVulnerability management vendor Rapid7 has launched a new community-driven platform that allows security professionals to exchange information about emerging flaws to better understand their impact and determine likelihood of those vulnerabilities being exploited by attackers. Called AttackerKB, the platform was launched as a closed beta program in January and was opened to the public April […]
newswww.csoonline.comApr 16, 2020, 10:00 AM- April 2020 Patch Tuesday forecast: Uncertainty reigns, but patching endures through pandemicHelp Net Security
I should have reserved the title from last month’s article – Let’s put the madness behind us for this month. Of course, it has a completely different meaning now in the wake of the COVID-19 pandemic chaos. The biggest change and challenge for most of us is managing and securing an IT environment while working from home. Extending the edge of the corporate network through VPNs has taxed many environments, placing greater reliance on collaboration … More →
newswww.helpnetsecurity.comApr 10, 2020, 6:32 AM - 6th April – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 6th April 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches A new campaign of the Zeus Sphinx banker is targeting clients of US, Canadian and Australian banks using COVID-19 themed emails. Emails titled “COVID 19 relief” contain password-protected Word documents with […]
vendorresearch.checkpoint.comApr 6, 2020, 2:15 PM - Security Affairs newsletter Round 258Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Coronavirus-themed attacks March 22 – March 28, 2020 FIN7 hackers target enterprises with weaponized USB drives via USPS Source code of Dharma ransomware now surfacing on public hacking forums Crooks leverage Zooms popularity in Coronavirus outbreak to serve […]
newssecurityaffairs.comApr 5, 2020, 9:23 AM - Experts published PoC exploits for CVE-2020-0796 privilege escalation flaw on WindowsSecurity Affairs
Researchers published proof-of-concept (PoC) exploits for the CVE-2020-0796 Windows flaw, tracked as SMBGhost, that can be exploited for local privilege escalation. Researchers Daniel García Gutiérrez (@danigargu) and Manuel Blanco Parajón (@dialluvioso_) have published proof-of-concept (PoC) exploits for the CVE-2020-0796 Windows vulnerability, tracked as SMBGhost, that can be exploited by attackers for local privilege escalation. Cybersecurity firms Kryptos […]
newssecurityaffairs.comApr 1, 2020, 11:38 AM Researchers have published proof-of-concept (PoC) exploits to demonstrate that the Windows vulnerability tracked as SMBGhost and CVE-2020-0796 can be exploited for local privilege escalation.
newswww.securityweek.comApr 1, 2020, 9:09 AMSome users have complained that the Windows security update released recently by Microsoft to patch a wormable vulnerability related to Server Message Block 3.0 (SMBv3) is causing problems.
newswww.securityweek.comMar 17, 2020, 12:59 PM- 16th March – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 16th March 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches A campaign leveraging the COVID-19 pandemic to target the Mongolian government and public sector has been detected by Check Point Research. The campaign, attributed to a China-linked APT group, used spear-phishing […]
vendorresearch.checkpoint.comMar 16, 2020, 3:09 PM - Security Affairs newsletter Round 255Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Facebook sues Namecheap to protect people from domain name fraud Netgear fixes a critical RCE that could allow to takeover Flagship Nighthawk routers New Coronavirus-themed malspam campaign delivers FormBook Malware The City of Durham shut down its network […]
newssecurityaffairs.comMar 15, 2020, 3:30 PM - Week in review: Trojanized hacking tools, coronavirus scams, (IN)SECURE Magazine special issueHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and podcasts: The haphazard response to COVID-19 demonstrates the value of enterprise risk management Just 12% of more than 1,500 respondents believe their businesses are highly prepared for the impact of coronavirus, while 26% believe that the virus will have little or no impact on their business, according to a survey by Gartner. Coronavirus-themed scams and attacks intensify With the Western world conducting … More →
newswww.helpnetsecurity.comMar 15, 2020, 10:00 AM Microsoft has released out-of-band updates for Windows to patch a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that has been described as “wormable.”
newswww.securityweek.comMar 12, 2020, 7:23 PMMicrosoft released security updates to fix a recently disclosed CVE-2020-0796 vulnerability in SMBv3 protocol that could be abused by wormable malware. Microsoft has released security updates to address the CVE-2020-0796 vulnerability in SMBv3 protocol that could be exploited by vxers to implement “wormable” malware. On March 10, 2019, Microsoft accidentally leaked info on a security update for […]
newssecurityaffairs.comMar 12, 2020, 7:04 PM- Microsoft releases patch for leaked SMBv3 RCE flawHelp Net Security
After the inadvertent leaking of details about a wormable Windows SMBv3 RCE flaw (CVE-2020-0796) on Tuesday, Microsoft has rushed to release a patch (i.e., security updates). The flaw affects Windows 10 (versions 1903 and 1909) and Windows Server (1903 and 1909) installations, so admins who have those in their care are urged to implement the security updates right away. Those who can’t should at least disable SMBv3 compression, block TCP port 445 at the enterprise … More →
newswww.helpnetsecurity.comMar 12, 2020, 6:17 PM In March 2020, merely days after the scheduled Patch Tuesday update, Microsoft released an out-of-band patch for a new remote code execution (RCE) vulnerability, CVE-2020-0796. An out-of-band patch is typically released outside of regularly scheduled updates and often provided due to the possibility of a widespread threat, in this case a wormable RCE vulnerability. This vulnerability exists within the Microsoft Server Message Block 3.0 (SMBv3), specifically regarding malformed compression headers.
vendorunit42.paloaltonetworks.comMar 11, 2020, 5:15 PMMicrosoft is working on patches for a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that exposes systems to “wormable” attacks.
newswww.securityweek.comMar 11, 2020, 11:20 AM- Wormable Windows SMBv3 RCE flaw leaked, but not patchedHelp Net Security
Yesterday, when Microsoft released its regular Patch Tuesday fixes, Cisco Talos and Fortinet inadvertently(?) also published information about CVE-2020-0796, a “wormable” vulnerability in the Microsoft Server Message Block (SMB) protocol that has yet to be fixed. Cisco Talos has since removed the entry but, a few hours later, Microsoft published an advisory offering more information and workarounds to be implemented until a fix is made available. About CVE-2020-0796 CVE-2020-0796 is a remote code execution vulnerability … More →
newswww.helpnetsecurity.comMar 11, 2020, 10:42 AM Today Microsoft accidentally leaked info about a new wormable vulnerability (CVE-2020-0796) in the Microsoft Server Message Block (SMB) protocol. Today Microsoft accidentally leaked info on a security update for a wormable vulnerability in the Microsoft Server Message Block (SMB) protocol. The issue, tracked as CVE-2020-0796, is pre- remote code execution vulnerability that resides in the Server […]
newssecurityaffairs.comMar 10, 2020, 10:53 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-1464CVSS 7.8 · High
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and lo…
- CVE-2020-0986CVSS 7.8 · High
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This…
- CVE-2020-1054CVSS 7.8 · High
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulner…
- CVE-2020-1027CVSS 7.8 · High
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID…
- CVE-2020-1020CVSS 8.8 · High
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type…
- CVE-2020-0938CVSS 7.8 · High
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type…