Skip to content
COOEY

EXPOSURES › CVE-2020-0796

CVE-2020-0796

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0796 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

A critical SMBv3 vulnerability allowed remote code execution, actively exploited and linked to ransomware attacks, impacting DIB organizations reliant on Microsoft infrastructure.

CVE-2020-0796 in Microsoft's SMBv3 protocol enabled attackers to execute code on vulnerable servers and clients, leading to potential data breaches and system compromise. DIB organizations must ensure timely patching and network segmentation to mitigate this risk and maintain CMMC compliance. Failure to address this vulnerability exposes systems to ransomware and other malicious activity.

Shame score — The widespread exploitation of a critical vulnerability in a core Microsoft protocol, linked to ransomware, demonstrates a significant failure in security practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized