CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability
Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 99.8% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
Affected products
- Microsoft Windows 10 1903: affected versions not specified
- Microsoft Windows 10 1909: affected versions not specified
- Microsoft Windows Server 1903: affected versions not specified
- Microsoft Windows Server 1909: affected versions not specified
Published 2020-03-12. Last modified 2026-10-01.