February 10, 2022 · Applied Cybernetics Group
CVE-2020-0796 — Microsoft SMBv3
known ransomware use
Microsoft SMBv3 Remote Code Execution Vulnerability
- Added to KEV
2022-02-10- Federal due date
2022-08-10- Vendor
- Microsoft
- Product
- SMBv3
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-0796
CISA short description
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
Required action
Apply updates per vendor instructions.