
CVE-2020-0796 (SMBGhost) was one of the most feared Windows vulnerabilities after EternalBlue. It was a wormable remote code execution bug in SMBv3, meaning a specially crafted network packet could compromise a machine without user interaction. Beyond its impact, it's an excellent case study in Windows networking internals, SMB protocol parsing, kernel memory management, and why secure protocol implementation is so challenging. The vulnerability resides in how the srv2.sys driver handles compressed data packets. An integer overflow in the compression header leads to a buffer overflow, corrupting memory and enabling RCE. https://www.jamf.com/blog/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-poc-jamf-threat-labs/
Post summary
The post summarizes SMBGhost’s mechanics—an integer overflow leading to a buffer overflow in SMBv3—and points readers to a PoC, but it does not present active exploitation or patch details.





