Back

CVE-2020-0796

CRITICAL CISA KEV

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

Published: Mar 12, 2020 Modified: Aug 12, 2026
CWE-119 CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
microsoft windows_10_1903 -
microsoft windows_10_1903 -
microsoft windows_10_1903 -
microsoft windows_10_1909 -
microsoft windows_10_1909 -
microsoft windows_10_1909 -
microsoft windows_server_1903 -
microsoft windows_server_1909 -

GitHub Security Advisory GHSA-vh23-87v3-h8c6

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3...

References (15)

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 99.81%

Top 0% most likely to be exploited

Threat Score 99.9 / 100

CISA Known Exploited

Date Added: 2022-02-10
Due Date: 2022-08-10
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub