CVE-2020-0796
Microsoft SMBv3 Remote Code Execution Vulnerability
10.0
CVSS 3.1
99.8 %
EPSS (current)
2022-02-10
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / SMBv3
Published: 2020-03-12 · Due (CISA): 2022-08-10
CWE: CWE-119 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | network/cves/2020/CVE-2020-0796.yaml | Microsoft SMBv3 - Remote Code Execution | – |
| metasploit | exploit/windows/local/cve_2020_0796_smbghost | exploit/windows/local/cve_2020_0796_smbghost | 2020-03-13 |
| metasploit | exploit/windows/smb/cve_2020_0796_smbghost | exploit/windows/smb/cve_2020_0796_smbghost | 2020-03-13 |
| exploitdb | 48216 | Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC) | 2020-03-14 |
| exploitdb | 48267 | Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation | 2020-03-30 |
| exploitdb | 48537 | Microsoft Windows - 'SMBGhost' Remote Code Execution | 2020-06-02 |
References only — no downloads or instructions.