CVE-2020-0796

medium Microsoft ⚠️ CISA KEV — Exploited in the Wild
EPSS Score
99.8%
Exploitation probability in 30 days
Top 0% most likely to be exploited
Published: March 12, 2020 (2369 days ago)
Last Modified: August 12, 2026
Vendor: Microsoft
Source: MITRE

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2022-02-10
Remediation Due: 2022-08-10 (⚠ 1488d overdue)
Ransomware Campaign: Known

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

Affected Products

Microsoft Windows 10 Version 1903 for 32-bit SystemsMicrosoft Windows 10 Version 1903 for x64-based SystemsMicrosoft Windows 10 Version 1903 for ARM64-based SystemsMicrosoft Windows Server, version 1903 (Server Core installation)Microsoft Windows 10 Version 1909 for 32-bit SystemsMicrosoft Windows 10 Version 1909 for x64-based SystemsMicrosoft Windows 10 Version 1909 for ARM64-based SystemsMicrosoft Windows Server, version 1909 (Server Core installation)

References