Vulnerability record · CVE-2020-0796 · published 12 March 2020
CVE-2020-0796: Microsoft SMBv3 buffer overflow remote code execution
Microsoft · Windows 10 1903
CVE-2020-0796 is a remote code execution flaw in how Microsoft's SMB 3.1.1 protocol handles certain requests, caused by a memory buffer overflow (CWE-119). It affects Windows 10 1903/1909 and Windows Server 1903/1909, and because SMB is a core network service, an unauthenticated attacker can reach it over the network.
Description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network-reachable RCE, KEV-listed with known ransomware use, and near-maximum EPSS probability make this a top remediation priority.
What it is
CVE-2020-0796 is a remote code execution flaw in how Microsoft's SMB 3.1.1 protocol handles certain requests, caused by a memory buffer overflow (CWE-119). It affects Windows 10 1903/1909 and Windows Server 1903/1909, and because SMB is a core network service, an unauthenticated attacker can reach it over the network.
Impact
An attacker can execute arbitrary code on the target system, and the CVSS scope change (S:C) indicates impact can extend beyond the vulnerable SMB component. Given SMB's role, successful exploitation can lead to full system compromise.
Attack surface
Reached over the network via SMBv3 traffic (CVSS AV:N, AC:L, PR:N, UI:N), so no authentication or user interaction is required. Both SMBv3 client and server roles are implicated by the description.
Exploitation
CVE-2020-0796 is listed in CISA KEV (added 2022-02-10) with known ransomware campaign use, and EPSS 30-day probability is 0.9981 (99.958th percentile). Multiple references are tagged Exploit, including pre-authentication proof-of-concept material.
What to do
- Apply the Microsoft vendor patch referenced in the MSRC advisory for CVE-2020-0796.
- If patching cannot be done immediately, disable SMBv3 compression on affected hosts as a temporary workaround.
- Block SMB (TCP 445) at network boundaries and restrict internal SMB exposure to trusted segments.
- Inventory Windows 10 1903/1909 and Windows Server 1903/1909 systems and prioritize them for remediation.
- Monitor for and remove any unauthorized SMB listeners or relay infrastructure on the network.
Detection
- Monitor SMBv3 traffic for malformed compression headers or anomalous SMB 3.1.1 negotiation patterns.
- Alert on unexpected outbound SMB connections from workstations and servers.
- Review host logs for crashes or restarts of the SMB service (srv2.sys / mrxsmb) that could indicate exploitation attempts.
- Hunt for known SMBGhost proof-of-concept artifacts or tooling names on endpoints and in network logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-0796 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft SMBv3 Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-0796 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-0796), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.