Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
On 11 March 2020, Microsoft shipped a fix for CVE-2020-0796, a wormable remote code execution flaw in how Windows 10 and Windows Server handle compressed SMBv3 packets. An attacker could send a specially crafted compressed packet and trigger a buffer overflow before authentication, exactly the class of bug security people fear could be chained into self-spreading malware. Researchers named it SMBGhost, published proof-of-concepts within days, demonstrated local privilege escalation chains, and Microsoft followed with an out-of-band patch update on 12 March. This technical retrospective covers the flaw mechanics, the compression workaround, the patch wave, and why the wormable nightmare never fully materialized.