Input validation error in Microsoft Windows and Windows Server - CVE-2020-0796
Published: March 11, 2020 / Updated: June 14, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. A remote attacker can trick a client to connect to a malicious SMB server and execute arbitrary code on the system.
Affected software
Windows Server
How to mitigate CVE-2020-0796
Links to Public Exploits and PoC-codes
- Exploit #9104 - CVE-2020-0796 (WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.) (June 14, 2023)
- Exploit #8085 - CVE-SMBGhost-Windows-10 (This repository shows how to exploit the vulnerability SMBGhost in a Windows 10 Machine for executing a remote code execution and opening a shell ) (June 27, 2022)
- Exploit #7093 - CVE-2020-0796-exp () (November 29, 2021)
- Exploit #5516 - CVE-2020-0796 (local exploit) (June 1, 2021)
- Exploit #5461 - SMBv3 Compression Buffer Overflow (May 21, 2021)
- Exploit #5141 - SMBGhost_Crash_Poc (CVE-2020-0796.SMBGhost_Crash_Poc ) (February 11, 2021)
- Exploit #5123 - smbghost-5 (CVE-2020-0796. Smbghost Local Privilege Escalation) (February 7, 2021)
- Exploit #5015 - CVE-2020-0796 (local exploit) (January 11, 2021)
- Exploit #4867 - LPE---CVE-2020-0796 () (November 21, 2020)
- Exploit #4847 - CVE-2020-0796 () (November 17, 2020)
- Exploit #4802 - CVE-2020-0796-POC (CVE-2020-0796-POC) (November 6, 2020)
- Exploit #4801 - CVE-2020-0796-EXP (CVE-2020-0796-EXP) (November 6, 2020)
- Exploit #4686 - cve_2020_0796 () (October 10, 2020)
- Exploit #4661 - SMBGhost-CVE-2020-0796- (To crash Windows-10 easily) (September 28, 2020)
- Exploit #4639 - CVE-2020-0796-BOF () (September 21, 2020)
- Exploit #4637 - CVE-2020-0796-cobaltstrike-cna (cobaltstrike cna for CVE-2020-0796) (September 21, 2020)
- Exploit #4533 - smbghost (SMBGhost(CVE-2020-0796) is a Security Vulnerability with wormlike features, that affects Windows 10 computers and was first reported publicly on 10 March 2020. Proof-of-Concept exploit code was published 1 June 2020 on Github by a security resea (September 1, 2020)
- Exploit #4520 - NSE-scripts (NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473) (August 21, 2020)
- Exploit #3925 - SMBGhost_Scanner (Advanced scanner for CVE-2020-0796 - SMBv3 RCE ) (August 10, 2020)
- Exploit #3597 - SMBGhost_Scanner (Advanced scanner for CVE-2020-0796 - SMBv3 RCE ) (July 25, 2020)
- Exploit #3540 - NSE-scripts (NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST) (July 20, 2020)
- Exploit #3543 - CVE-2020-0796 (CVE-2020-0796 POC) (July 20, 2020)
- Exploit #3488 - SMBGhost-SMBleed-scanner (SMBGhost (CVE-2020-0796) and SMBleed (CVE-2020-1206) Scanner) (July 15, 2020)
- Exploit #3464 - SMBGhost-LPE-Metasploit-Module (This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework) (July 15, 2020)
- Exploit #3097 - smbghost (CVE-2020-0796. Smbghost Local Privilege Escalation) (July 15, 2020)
- Exploit #3041 - SMBGhost_AutomateExploitation (SMBGhost (CVE-2020-0796) Automate Exploitation and Detection) (June 19, 2020)
- Exploit #3018 - CVE-2020-0796-RCE-POC (CVE-2020-0796 Remote Code Execution POC) (June 10, 2020)
- Exploit #2900 - CVE-2020-0796-LPE-POC (CVE-2020-0796 Local Privilege Escalation POC) (June 3, 2020)
- Exploit #2901 - CVE-2020-0796-EXP (CVE-2020-0796-EXP) (June 3, 2020)
- Exploit #2903 - CVE_2020_0796_CNA (Cobalt Strike AggressorScripts CVE-2020-0796) (June 3, 2020)
- Exploit #2904 - CVE-2020-0796 (Lightweight PoC and Scanner for CVE-2020-0796 without authentication.) (June 3, 2020)
- Exploit #2906 - CVE-2020-0796-SMB (该资源为CVE-2020-0796漏洞复现,包括Python版本和C++版本。主要是集合了github大神们的资源,希望您喜欢~) (June 3, 2020)
- Exploit #2909 - cve-2020-0796 (CVE-2020-0796 (SMBGhost) LPE) (June 3, 2020)
- Exploit #2922 - cve-2020-0796-Scanner (This tool helps scan large subnets for cve-2020-0796 vulnerable systems) (June 3, 2020)
- Exploit #2924 - CVE-2020-0796 (Powershell SMBv3 Compression checker) (June 3, 2020)
- Exploit #2935 - CVE-2020-0796 (PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)) (June 3, 2020)
- Exploit #2940 - CVE-2020-0796 () (June 3, 2020)
- Exploit #2942 - CVE-2020-0796 () (June 3, 2020)
- Exploit #2966 - SMBGhostScanner (SMBGhost CVE-2020-0796) (June 3, 2020)
- Exploit #2980 - CVE-2020-0796-LPE () (June 3, 2020)
- Exploit #3003 - CVE-2020-0796 () (June 3, 2020)
- Exploit #3007 - Input validation error (June 3, 2020)
- Exploit #3008 - CVE-2020-0796 (CVE-2020-0796) (June 3, 2020)
- Exploit #3010 - SMBGhost (批量测试CVE-2020-0796 - SMBv3 RCE) (June 3, 2020)
- Exploit #3012 - CVE-2020_0796-exp (CVE-2020_0796-exp) (June 3, 2020)
- Exploit #2860 - smbee (Check system is vulnerable CVE-2020-0796 (SMB v3)) (June 3, 2020)
- Exploit #2861 - CVE-2020-0796 () (June 3, 2020)
- Exploit #2862 - SMBCompScan (Scanner script to identify hosts vulnerable to CVE-2020-0796) (June 3, 2020)
- Exploit #2863 - SMBGhost (SMBGhost (CVE-2020-0796) threaded scanner) (June 3, 2020)
- Exploit #2864 - SMBGhosts (Multithreaded Scanner for CVE-2020-0796 - SMBv3 RCE) (June 3, 2020)
- Exploit #2865 - CVE-2020-0796 (SMBv3 RCE vulnerability in SMBv3) (June 3, 2020)
- Exploit #2866 - SMBGhost (Scanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE ) (June 3, 2020)
- Exploit #2867 - CVE-2020-0796 (CVE-2020-0796 - Working PoC - 20200313) (June 3, 2020)
- Exploit #2868 - SMBScanner (Multithread SMB scanner to check CVE-2020-0796 for SMB v3.11) (June 3, 2020)
- Exploit #2869 - SMBGhost-WorkaroundApplier (This script will apply the workaround for the vulnerability CVE-2020-0796 for the SMBv3 unauthenticated RCE) (June 3, 2020)
- Exploit #2870 - CVE-2020-0796 (CVE-2020-0796 SMBGhost) (June 3, 2020)
- Exploit #2871 - cve-2020-0796 () (June 3, 2020)
- Exploit #2872 - SMBv3.1.1-scan---CVE-2020-0796 (Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)) (June 3, 2020)
- Exploit #2873 - CVE-2020-0796 (CVE-2020-0796 Python POC buffer overflow) (June 3, 2020)
- Exploit #2874 - GUI-Check-CVE-2020-0976 () (June 3, 2020)
- Exploit #2876 - CVE-2020-0796-PoC (PoC for triggering buffer overflow via CVE-2020-0796) (June 3, 2020)
- Exploit #2877 - SMBGhost (Advanced scanner for CVE-2020-0796 - SMBv3 RCE ) (June 3, 2020)
- Exploit #2878 - CVE-2020-0796-Scanner (CVE-2020-0796-Scanner) (June 3, 2020)
- Exploit #2879 - Unauthenticated-CVE-2020-0796-PoC (An unauthenticated PoC for CVE-2020-0796) (June 3, 2020)
- Exploit #2880 - CVE-2020-0796-PoC-and-Scan (Lightweight PoC and Scanner for CVE-2020-0796 without authentication.) (June 3, 2020)
- Exploit #2881 - CVE-2020-0796 (Scanner for CVE-2020-0796) (June 3, 2020)
- Exploit #2882 - aioScan_CVE-2020-0796 (基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。) (June 3, 2020)
- Exploit #2883 - SMBGhost_Crash_Poc (CVE-2020-0796.SMBGhost_Crash_Poc ) (June 3, 2020)
- Exploit #2884 - cve2020-0796 () (June 3, 2020)
- Exploit #2885 - smbghost (CVE-2020-0796_CoronaBlue_SMBGhost) (June 3, 2020)
- Exploit #2889 - CVE-2020-0796-DoS (DoS PoC for CVE-2020-0796 (SMBGhost)) (June 3, 2020)
- Exploit #2894 - cve-2020-0796-vuln () (June 3, 2020)
- Exploit #2896 - CVE-2020-0796-LPE (SMBGHOST local privilege escalation) (June 3, 2020)
- Exploit #2898 - CVE-2020-0796 () (June 3, 2020)
- Exploit #2812 - Microsoft Windows - 'SMBGhost' Remote Code Execution (June 3, 2020)
- Exploit #2811 - Microsoft Windows SMBGhost Remote Code Execution (June 2, 2020)
- Exploit #2802 - CVE-2020-0797 (Exploiter la vulnérabilité CVE-2020-0796, Remote Code Execution du protocole SMB 3.1.1 (SMBv3).) (June 2, 2020)
- Exploit #2364 - cve2020-0796 (Microsoft SMV3.1.1 wormable Exploit) (April 7, 2020)
- Exploit #2264 - CVE2020-0796 (Exploit for win10 SMB3.1) (April 5, 2020)
- Exploit #2258 - SMBv3 Compression Buffer Overflow (April 3, 2020)
- Exploit #2253 - Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation (April 2, 2020)
- Exploit #2248 - CVE-2020-0796 (Coronablue exploit) (March 31, 2020)
- Exploit #2244 - CVE-2020-0796-LPE-EXP (Windows SMBv3 LPE exploit 已编译版) (March 31, 2020)
- Exploit #2239 - CVE-2020-0796 (PoC with remote code execution module for CVE-2020-0796 aka SMBGhost.) (March 31, 2020)
- Exploit #2238 - CVE-2020-0796 (CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost) (March 31, 2020)
- Exploit #2210 - CVE-2020-0796-Scanner (CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner) (March 18, 2020)
- Exploit #2211 - GitHub - xax007/CVE-2020-0796-Scanner: CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner (March 18, 2020)
- Exploit #2222 - CVE-2020-0796 () (March 18, 2020)
- Exploit #2082 - CVE-2020-0796 (Exploiter la vulnérabilité CVE-2020-0796, Remote Code Execution du protocole SMB 3.1.1 (SMBv3).) (March 18, 2020)
- Exploit #337 - Scanners-for-CVE-2020-0796-Testing (Scanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796) ) (March 18, 2020)
- Exploit #338 - CVE-2020-0796-PoC (Weaponized PoC for SMBv3 TCP codec/compression vulnerability) (March 18, 2020)
- Exploit #339 - DisableSMBCompression (CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates) (March 18, 2020)
- Exploit #340 - # CVE-2020-0796 (March 18, 2020)
- Exploit #341 - CVE-2020-0796 (NSE script to detect vulnerable CVE-2020-0796 issue "SMBGhost") (March 18, 2020)
- Exploit #342 - CVE-2020-0796-Checker (Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)) (March 18, 2020)
- Exploit #343 - cve-2020-0796-scanner (This project is used for scanning cve-2020-0796 SMB vulnerability) (March 18, 2020)
- Exploit #344 - CVE-2020-0796 () (March 18, 2020)
- Exploit #345 - # CVE-2020-0796 (March 18, 2020)
- Exploit #346 - cve-2020-0796 (Identifying and Mitigating the CVE-2020–0796 flaw in the fly) (March 18, 2020)
- Exploit #347 - CVE2020-0796 (CVE2020-0796 SMBv3 RCE) (March 18, 2020)
- Exploit #348 - SMBGhost (Scanner for CVE-2020-0796 - SMBv3 RCE) (March 18, 2020)
- Exploit #349 - CVE-2020-0796-PoC ( CVE-2020-0796 - a wormable SMBv3 vulnerability. ) (March 18, 2020)
- Exploit #350 - eternalghosttest (This repository contains a test case for CVE-2020-0796) (March 18, 2020)
- Exploit #1463 - Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC) (March 18, 2020)