KEV · Actively exploited
CVE-2020-0796
CRITICAL 10.0
KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
99.81%
exploit likely
percentile 100.0%
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-02-10
- Remediation deadline
- 2022-08-10
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows 10 1909 · 2019-09 Fixed in —
- Windows 10 1903 · 2019-03 Fixed in —