CISA Known Exploited Vulnerability

CVE-2020-0796 Ransomware

Microsoft · SMBv3

Microsoft SMBv3 Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-119
Ransomware Known

CISA description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

Required action

Apply updates per vendor instructions.