← voltar
CVE-2020-0796

CVE-2020-0796

CVSS 10 CRITICALEPSS 99.8%● KEVCWE-119
Em resumo

Uma falha crítica no protocolo SMBv3 do Windows (usado para compartilhamento de arquivos) permite que atacantes executem código malicioso remotamente em computadores vulneráveis sem precisar de permissões especiais. É particularmente perigosa porque SMBv3 é amplamente usado em redes e o ataque requer mínima interação.

Detalhe técnico

Vulnerabilidade de execução remota de código no protocolo SMBv3 (CWE-119: buffer overflow) acionada por requisições de rede especialmente criadas. Vetor de ataque é pela rede sem autenticação necessária; sistemas afetados processam automaticamente pacotes SMBv3 maliciosos que corrompem memória e resultam em execução de código arbitrário com privilégios do sistema.

Resumo gerado e traduzido por IA a partir da descrição oficial.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PoCs públicas encontradas97
githubgithub.com/danigargu/CVE-2020-07961357githubgithub.com/ly4k/SMBGhost717githubgithub.com/jamf/CVE-2020-0796-RCE-POC573githubgithub.com/Barriuso/SMBGhost_AutomateExploitation347githubgithub.com/eerykitty/CVE-2020-0796-PoC333githubgithub.com/jamf/CVE-2020-0796-LPE-POC245githubgithub.com/Rvn0xsy/CVE_2020_0796_CNA75githubgithub.com/rsmudge/CVE-2020-0796-BOF70githubgithub.com/jiansiting/CVE-2020-079664githubgithub.com/ioncodes/SMBGhost58githubgithub.com/k8gege/PyLadon51githubgithub.com/jamf/SMBGhost-SMBleed-scanner44githubgithub.com/eastmountyxz/CVE-2020-0796-SMB33githubgithub.com/T13nn3s/CVE-2020-079628githubgithub.com/maxpl0it/Unauthenticated-CVE-2020-0796-PoC22githubgithub.com/Almorabea/SMBGhost-LPE-Metasploit-Module20githubgithub.com/gabimarti/SMBScanner19githubgithub.com/0x25bit/CVE-2020-0796-PoC19githubgithub.com/ButrintKomoni/cve-2020-079617githubgithub.com/f1tz/CVE-2020-0796-LPE-EXP17githubgithub.com/GuoKerS/aioScan_CVE-2020-079615githubgithub.com/dickens88/cve-2020-0796-scanner14githubgithub.com/joaozietolie/CVE-2020-0796-Checker14githubgithub.com/w1ld3r/SMBGhost_Scanner14githubgithub.com/thelostworldFree/CVE-2020-079611githubgithub.com/jiansiting/CVE-2020-0796-Scanner9githubgithub.com/technion/DisableSMBCompression9githubgithub.com/0xeb-bp/cve-2020-07967githubgithub.com/dungnm24/CVE-2020-07966githubgithub.com/vysecurity/CVE-2020-07965githubgithub.com/orangmuda/CVE-2020-07965githubgithub.com/tango-j/CVE-2020-07964githubgithub.com/wneessen/SMBCompScan4githubgithub.com/sujitawake/smbghost3githubgithub.com/exp-sky/CVE-2020-07963githubgithub.com/codewithpradhan/SMBGhost-CVE-2020-0796-2githubgithub.com/Jagadeesh7532/-CVE-2020-0796-SMBGhost-Windows-10-SMBv3-Remote-Code-Execution-Vulnerability2githubgithub.com/MasterSploit/LPE---CVE-2020-07962githubgithub.com/TinToSer/CVE-2020-0796-LPE2githubgithub.com/Anonimo501/SMBGhost_CVE-2020-0796_checker2githubgithub.com/laolisafe/CVE-2020-07962githubgithub.com/DannyRavi/nmap-scripts2githubgithub.com/cory-zajicek/CVE-2020-0796-DoS1githubgithub.com/awareseven/eternalghosttest1githubgithub.com/Dhoomralochana/Scanners-for-CVE-2020-0796-Testing1githubgithub.com/netscylla/SMBGhost1githubgithub.com/BinaryShadow94/SMBv3.1.1-scan---CVE-2020-07961githubgithub.com/ran-sama/CVE-2020-07961githubgithub.com/julixsalas/CVE-2020-07961githubgithub.com/LabDookhtegan/CVE-2020-0796-EXP1githubgithub.com/datntsec/CVE-2020-07961githubgithub.com/1stPeak/CVE-2020-0796-Scanner1githubgithub.com/F6JO/CVE-2020-0796-Batch-scanning1githubgithub.com/arzuozkan/CVE-2020-07961githubgithub.com/SEHandler/CVE-2020-07961githubgithub.com/OldDream666/cve-2020-07961githubgithub.com/AdamSonov/smbGhostCVE-2020-07961githubgithub.com/bsec404/CVE-2020-07961githubgithub.com/cybermads/CVE-2020-07961githubgithub.com/1060275195/SMBGhost0githubgithub.com/Almorabea/SMBGhost-WorkaroundApplier0githubgithub.com/UraSecTeam/smbee0githubgithub.com/xax007/CVE-2020-0796-Scanner0githubgithub.com/AaronCaiii/CVE-2020-0796-POC0githubgithub.com/maqeel-git/CVE-2020-07960githubgithub.com/kn6869610/CVE-2020-07960githubgithub.com/esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-0githubgithub.com/tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo0githubgithub.com/intelliroot-tech/cve-2020-0796-Scanner0githubgithub.com/section-c/CVE-2020-07960githubgithub.com/bacth0san96/SMBGhostScanner0githubgithub.com/halsten/CVE-2020-07960githubgithub.com/ysyyrps123/CVE-2020-07960githubgithub.com/ysyyrps123/CVE-2020-0796-exp0githubgithub.com/tripledd/cve-2020-0796-vuln0githubgithub.com/wsfengfan/CVE-2020-07960githubgithub.com/Opensitoo/cve-2020-07960githubgithub.com/Murasame-nc/CVE-2020-0796-LPE-POC0githubgithub.com/lisinan988/CVE-2020-0796-exp0githubgithub.com/vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-0githubgithub.com/nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE0githubgithub.com/thai1012/cve-2020-07960githubgithub.com/TweatherQ/CVE-2020-07960githubgithub.com/krizzz07/CVE-2020-07960githubgithub.com/Justjeff211/conti-ransomware-writeup0githubgithub.com/hungdnvp/POC-CVE-2020-07960githubgithub.com/z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-Vulnerabilities0githubgithub.com/monjheta/CVE-2020-07960cve_referencepacketstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.htmlnão verificadocve_referencepacketstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.htmlnão verificadocve_referencepacketstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/48267não verificadocve_referencepacketstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.htmlnão verificadocve_referencepacketstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/48537não verificadoexploitdbwww.exploit-db.com/exploits/48216não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →