EXPOSURES › CVE-2020-0796
CVE-2020-0796
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical SMBv3 vulnerability allowed remote code execution, actively exploited and linked to ransomware attacks, impacting DIB organizations reliant on Microsoft infrastructure.
CVE-2020-0796 in Microsoft's SMBv3 protocol enabled attackers to execute code on vulnerable servers and clients, leading to potential data breaches and system compromise. DIB organizations must ensure timely patching and network segmentation to mitigate this risk and maintain CMMC compliance. Failure to address this vulnerability exposes systems to ransomware and other malicious activity.
Shame score — The widespread exploitation of a critical vulnerability in a core Microsoft protocol, linked to ransomware, demonstrates a significant failure in security practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |