CVE-2020-0796

critical

Description

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

From the Tenable Blog

CVE-2020-0796: "Wormable" Remote Code Execution Vulnerability in Microsoft Server Message Block SMBv3 (ADV200005)
CVE-2020-0796: "Wormable" Remote Code Execution Vulnerability in Microsoft Server Message Block SMBv3 (ADV200005)

Published: 2020-03-11

Critical unpatched “wormable” remote code execution (RCE) vulnerability in Microsoft Server Message Block 3.1.1 (SMBv3), dubbed EternalDarkness, disclosed by Microsoft. Update 03/13/2020: The Proof-of-concept section has been updated to reflect the public availability of an exploit script that can trigger a crash on a vulnerable system.

References

https://github.com/chengbochuan3/CVE-Windows-Protocol

https://github.com/CVEasy/cveasy-mcp

https://github.com/HermesNA-1/SnakeSploit

https://github.com/VillainSquad-WH/CVE-BugReproduction

https://github.com/korneevscp/osint-target

https://github.com/BL3IP/port-vuln-scanner

https://github.com/p4ncontomat3/smbghost

https://github.com/harshweb-cyber/Netscout

https://github.com/Akalka/Ai-Windows-Penetration-testing-Assistant-

https://github.com/mentalEdge984/ReconIQ

https://github.com/average-joe44/CVE-2020-0796-Forked-

https://github.com/s4mjx/Portscanner-py

https://github.com/Sombra-1/vulnmind

https://github.com/Justjeff211/conti-ransomware-writeup

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/yashtony/network-vulnerability-scanner

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/F45elix/network-vuln-scanner

https://github.com/Gorstak-Zadar/Patcher

https://github.com/nichxlxs/cve-research

https://github.com/CVE-ORG/CVE-ORG

https://github.com/thai1012/cve-2020-0796

https://github.com/hackingyseguridad/smb

https://github.com/nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE

https://github.com/maqeel-git/CVE-2020-0796

https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation

https://github.com/Chrisync/CVE-Scanner

https://github.com/DannyRavi/nmap-scripts

https://github.com/DannyRavi/nmap-cve-2020-1350

https://github.com/madanokr001/CVE-2020-0796

https://github.com/monjheta/CVE-2020-0796

https://github.com/Kaizzzo1/cve-2020-00796

https://github.com/mtai83/khai-th-c-CVE

https://github.com/z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-Vulnerabilities

https://github.com/heeloo123/CVE-2020-0796

https://github.com/TweatherQ/CVE-2020-0796

https://github.com/vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-

https://github.com/whoismept/IronSharp

https://github.com/CnHack3r/Awesome-hacking-tools

https://github.com/5l1v3r1/SMBGhosts

https://github.com/F6JO/CVE-2020-0796-Batch-scanning

https://github.com/thomsdev/CVE-2020-0796

https://github.com/rakhanobe/CVE-2020-0796

https://github.com/onsecuredev/CVE-2020-0796

https://github.com/byteofjoshua/CVE-2020-0796

https://github.com/Haruster/Apasys-CVE-2020-0796

https://github.com/5l1v3r1/smbghost-5

https://github.com/ZecOps/SMBGhost-SMBleed-scanner

https://github.com/Almorabea/SMBGhost-LPE-Metasploit-Module

https://github.com/1060275195/SMBGhost

https://github.com/Barriuso/SMBGhost_AutomateExploitation

https://github.com/exp-sky/CVE-2020-0796

https://github.com/ysyyrps123/CVE-2020-0796-exp

https://github.com/ysyyrps123/CVE-2020-0796

https://github.com/bacth0san96/SMBGhostScanner

https://github.com/ZecOps/CVE-2020-0796-RCE-POC

https://github.com/awsassets/CVE-2020-0798

https://github.com/0xeb-bp/cve-2020-0796

https://github.com/Rvn0xsy/CVE_2020_0796_CNA

https://github.com/LabDookhtegan/CVE-2020-0796-EXP

https://github.com/5l1v3r1/SMBGhost_Crash_Poc

https://github.com/bonesg/CVE-2020-0797

https://github.com/julixsalas/CVE-2020-0796

https://github.com/sujitawake/smbghost

https://github.com/jiansiting/CVE-2020-0796-Scanner

https://github.com/GuoKerS/aioScan_CVE-2020-0796

https://github.com/w1ld3r/SMBGhost_Scanner

https://github.com/BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796

https://github.com/marcinguy/CVE-2020-0796

https://github.com/IAreKyleW00t/SMBGhosts

https://github.com/Almorabea/SMBGhost-WorkaroundApplier

https://github.com/gabimarti/SMBScanner

https://github.com/ioncodes/SMBGhost

https://github.com/wneessen/SMBCompScan

https://github.com/netscylla/SMBGhost

https://github.com/UraSecTeam/smbee

https://github.com/xax007/CVE-2020-0796-Scanner

https://github.com/awareseven/eternalghosttest

https://github.com/psc4re/NSE-scripts

https://github.com/joaozietolie/CVE-2020-0796-Checker

https://github.com/ly4k/SMBGhost

https://github.com/technion/DisableSMBCompression

https://github.com/eastmountyxz/CSDNBlog-Security-Based

https://github.com/k8gege/PyLadon

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0796

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796

http://packetstormsecurity.com/files/157110/SMBv3-Compression-Buffer-Overflow.html

http://packetstormsecurity.com/files/156732/Microsoft-Windows-SMB-3.1.1-Remote-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2020-03-12

Updated: 2026-08-12

Named Vulnerability: SMBGhostNamed Vulnerability: EternalDarknessKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.9981