CVE-2020-0796PoC(microsoft / windows_10_1903)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1903 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1903
  • windows_10_1909
  • windows_server_1903
  • windows_server_1909

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-28); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1903windows_10_1909windows_server_1903windows_server_1909

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-28: 1Mentions · 2026-04-30: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Mentions · 2026-08-26: 1Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-03-28: 1PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-09-07: 1Exploit Tool / Code · 2026-03-28: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-30: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-08-26: 103-2804-3006-2506-2708-2609-07
Signal classification4 categories
PoC
233.3%
Disclosure
233.3%
Patch
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
PoC1
2026-04-301
Patch1
2026-06-251
Disclosure1
2026-06-271
General1
2026-08-261
Disclosure1
2026-09-071
PoC1
Full discourse6 posts
  • OS Dev@OSdev_
    Disclosure

    CVE-2020-0796 (SMBGhost) was one of the most feared Windows vulnerabilities after EternalBlue. It was a wormable remote code execution bug in SMBv3, meaning a specially crafted network packet could compromise a machine without user interaction. Beyond its impact, it's an excellent case study in Windows networking internals, SMB protocol parsing, kernel memory management, and why secure protocol implementation is so challenging. The vulnerability resides in how the srv2.sys driver handles compressed data packets. An integer overflow in the compression header leads to a buffer overflow, corrupting memory and enabling RCE. https://www.jamf.com/blog/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-poc-jamf-threat-labs/

    Post summary

    The post summarizes SMBGhost’s mechanics—an integer overflow leading to a buffer overflow in SMBv3—and points readers to a PoC, but it does not present active exploitation or patch details.

    26043252.9K
    4.8K followersView on X
  • Joe@JoePostingg
    Patch

    I'm sure AI powered zero days will become part of the threat landscape, but Shodan's top vulnerability is CVE-2020-0796. Its a wormable RCE that was patched in June 2020.

    Post summary

    The tweet highlights CVE‑2020‑0796, notes it is a wormable remote code execution flaw, and confirms it received a patch in June 2020.

    0002011.6K
    20.3K followersView on X
  • nol@nol_tech
    PoC

    @kmkz_security @ZecOps only know them because of their nice smbleed/ghost poc https://github.com/jamf/CVE-2020-0796-RCE-POC

    Post summary

    The tweet reveals that a PoC for CVE‑2020‑0796 is available and links to it, but offers no evidence of exploitation, patching, or technical details.

    0002092
    843 followersView on X
  • AHANONYE@Claver042
    General

    CVE-2018-13379 – Fortinet FortiOS SSL VPN Arbitrary File Read and CVE-2020-0796 – Windows SMBGhost Remote Code Execution. This lab strengthens my threat hunting, log analysis, and incident response skills while improving my understanding of real-world attacker techniques.

    Post summary

    The statement references CVE-2018-13379 and CVE-2020-0796 and notes that a lab using these CVEs helped improve threat hunting and incident response skills, but provides no PoCs, exploits, or active exploitation details.

    1000047
    304 followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    🚨URGENT ADVISORY🚨CVE-2020-0796, known as SMBGhost or CoronaBlue, is a critical remote code execution vulnerability affecting Microsoft’s SMBv3 (3.1.1) protocol. CLICK HERE FOR MORE INFORMATION 👇 https://cirt.gov.jm/advisory/smbghost-cve-2020-0796-persistently-recurring-critical-smbv3-vulnerability-jamaican #JaCIRT #NSOC #SMBGhost #Microsoft #Vulnerability https://t.co/1y13ZkMn7j

    Post summary

    The tweet announces the discovery of CVE-2020-0796, outlines its critical RCE nature in SMBv3, and links to an advisory, but does not provide any PoC, exploit, or patch details.

    0000084
    1.2K followersView on X
  • Git Rated@GitRated
    PoC

    A new AI review! danigargu/CVE-2020-0796 ⭐2.4/5.0 This repository provides a proof-of-concept local privilege escalation (LPE) exploit for **CVE-2020-0796 (SMBGhost/CoronaBlue)** targeting Windows SMBv3. https://gitrated.com/danigargu/CVE-2020-0796

    Post summary

    The repository hosts a proof‑of‑concept local privilege escalation exploit for CVE‑2020‑0796 (SMBGhost/CoronaBlue) targeting Windows SMBv3, with the code linked for reference.

    00000240
    24 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1903--arm64
OSmicrosoftwindows_10_1903--x64
OSmicrosoftwindows_10_1903--x86
OSmicrosoftwindows_10_1909--arm64
OSmicrosoftwindows_10_1909--x64
OSmicrosoftwindows_10_1909--x86
OSmicrosoftwindows_server_1903--x64
OSmicrosoftwindows_server_1909--x64

Explore more