← Vulnerability feed

Vulnerability record · CVE-2020-0796 · published 12 March 2020

CVE-2020-0796: Microsoft SMBv3 buffer overflow remote code execution

Microsoft · Windows 10 1903

CVE-2020-0796 is a remote code execution flaw in how Microsoft's SMB 3.1.1 protocol handles certain requests, caused by a memory buffer overflow (CWE-119). It affects Windows 10 1903/1909 and Windows Server 1903/1909, and because SMB is a core network service, an unauthenticated attacker can reach it over the network.

10.0 CVSS 3.1 Critical CISA KEV since 10 Feb 2022 Known ransomware use EPSS 100% · top 0.1% CWE-119 · Memory buffer overflow
10.0CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
15References, 4 tagged exploit
12 Aug 2026Last modified by NVD

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network-reachable RCE, KEV-listed with known ransomware use, and near-maximum EPSS probability make this a top remediation priority.

What it is

CVE-2020-0796 is a remote code execution flaw in how Microsoft's SMB 3.1.1 protocol handles certain requests, caused by a memory buffer overflow (CWE-119). It affects Windows 10 1903/1909 and Windows Server 1903/1909, and because SMB is a core network service, an unauthenticated attacker can reach it over the network.

Impact

An attacker can execute arbitrary code on the target system, and the CVSS scope change (S:C) indicates impact can extend beyond the vulnerable SMB component. Given SMB's role, successful exploitation can lead to full system compromise.

Attack surface

Reached over the network via SMBv3 traffic (CVSS AV:N, AC:L, PR:N, UI:N), so no authentication or user interaction is required. Both SMBv3 client and server roles are implicated by the description.

Exploitation

CVE-2020-0796 is listed in CISA KEV (added 2022-02-10) with known ransomware campaign use, and EPSS 30-day probability is 0.9981 (99.958th percentile). Multiple references are tagged Exploit, including pre-authentication proof-of-concept material.

What to do

  • Apply the Microsoft vendor patch referenced in the MSRC advisory for CVE-2020-0796.
  • If patching cannot be done immediately, disable SMBv3 compression on affected hosts as a temporary workaround.
  • Block SMB (TCP 445) at network boundaries and restrict internal SMB exposure to trusted segments.
  • Inventory Windows 10 1903/1909 and Windows Server 1903/1909 systems and prioritize them for remediation.
  • Monitor for and remove any unauthorized SMB listeners or relay infrastructure on the network.

Detection

  • Monitor SMBv3 traffic for malformed compression headers or anomalous SMB 3.1.1 negotiation patterns.
  • Alert on unexpected outbound SMB connections from workstations and servers.
  • Review host logs for crashes or restarts of the SMB service (srv2.sys / mrxsmb) that could indicate exploitation attempts.
  • Hunt for known SMBGhost proof-of-concept artifacts or tooling names on endpoints and in network logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-0796 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft SMBv3 Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.h Third Party AdvisoryVDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796 PatchVendor Advisory
http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.h Third Party AdvisoryVDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796 PatchVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796 US Government Resource

Track CVE-2020-0796 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed8.4CVE-2021-33739Microsoft DWM Core Library elevation of privilegeCVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows …KEVEPSS 6.6%analysed8.1CVE-2020-0601Windows CryptoAPI ECC certificate validation spoofing flawWindows CryptoAPI (Crypt32.dll) improperly validates Elliptic Curve Cryptography certificates, allowing a spoofed code-signing certificate to be trus…KEVEPSS 89%analysed7.8CVE-2022-24521Windows CLFS Driver Out-of-Bounds Write Elevation of PrivilegeThe Windows Common Log File System (CLFS) driver contains an out-of-bounds write (CWE-787) that allows a local user to elevate privileges. Microsoft …KEVEPSS 7.1%analysed7.8CVE-2022-22718Windows Print Spooler local privilege escalationCVE-2022-22718 is an elevation of privilege flaw in the Windows Print Spooler. A local attacker with low privileges can exploit it to gain higher pri…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2020-0796), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.