LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-0796 to its Known Exploited Vulnerabilities catalog on Feb 10, 2022, with a federal patch deadline of Aug 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the…

CVE-2020-0796 is a remote code execution vulnerability in Microsoft’s Server Message Block 3.1.1 (SMBv3) protocol. An attacker who successfully exploits it can run code on a vulnerable server or client. Because the flaw has been used by ransomware operators, unpatched systems that expose or use SMBv3 remain a high-priority risk for IT and security teams.

Public detail is limited to the CISA description and the associated CWE; confirm exact affected builds, patch identifiers, and configuration guidance against the vendor advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In this case, the vulnerability exists in the way SMBv3 handles certain requests. A crafted request can cause the protocol implementation to mishandle memory, allowing an attacker to execute arbitrary code in the context of the affected SMBv3 service on either a server or a client.

Exploitation does not require the attacker to authenticate in the scenarios described by CISA; success depends on the target accepting and processing the malicious SMBv3 traffic. Specific packet formats, compression options, or trigger conditions are not detailed in the provided facts and must be verified against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Microsoft SMBv3 is commonly enabled on Windows servers and workstations that share files, printers, or other resources, and on clients that connect to those shares. It may also appear on systems that have the SMB client or server components installed even if file sharing is not actively used.

How to remediate

Apply the security updates published by Microsoft for this vulnerability, following the vendor’s instructions exactly as required by CISA. Patch both servers and clients that implement the affected SMBv3 handling.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used by ransomware, frequently lead to broader compromise and data theft. If you have reason to believe systems were reachable and unpatched while this issue was being exploited, treat the incident as a potential breach: isolate affected hosts, preserve logs, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SMBv3
WeaknessCWE-119
Added to CISA KEVFeb 10, 2022
Federal patch deadlineAug 10, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities