CVE-2020-0796

EUVD-2020-2283
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_10_1903
-
microsoftwindows_10_1903
-
microsoftwindows_10_1903
-
microsoftwindows_10_1909
-
microsoftwindows_10_1909
-
microsoftwindows_10_1909
-
microsoftwindows_server_1903
-
microsoftwindows_server_1909
-
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
1903 (arm64, x64, x86)
1909 (arm64, x64, x86)
Windows Server
1903 Server Core
1909 Server Core