Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.816800
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Server Message Block 3.1.1 RCE Vulnerability (KB4551762)
Summary:This host is missing a critical security; update according to Microsoft KB4551762
Description:Summary:
This host is missing a critical security
update according to Microsoft KB4551762

Vulnerability Insight:
The vulnerability is due to an error when the
SMBv3 handles maliciously crafted compressed data packets. Both SMB Servers and
clients are affected. To exploit the vulnerability against an SMB Server, an
unauthenticated attacker could send a specially crafted packet to a targeted SMBv3
Server. While as to exploit the vulnerability against an SMB Client, an
unauthenticated attacker would need to configure a malicious SMBv3 Server and
convince a user to connect to it.

Vulnerability Impact:
Successful exploitation will allow an attacker
to execute code on the target SMB Server or SMB Client.

Affected Software/OS:
SMB 3.1.1(SMBv3) on

- Windows 10 Version 1903 for 32-bit/x64-based Systems

- Windows 10 Version 1909 for 32-bit/x64-based Systems

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-0796
http://packetstormsecurity.com/files/156731/CoronaBlue-SMBGhost-Microsoft-Windows-10-SMB-3.1.1-Proof-Of-Concept.html
http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html
http://packetstormsecurity.com/files/156980/Microsoft-Windows-10-SMB-3.1.1-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html
http://packetstormsecurity.com/files/157901/Microsoft-Windows-SMBGhost-Remote-Code-Execution.html
http://packetstormsecurity.com/files/158054/SMBleed-SMBGhost-Pre-Authentication-Remote-Code-Execution-Proof-Of-Concept.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.