>

SMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3

On 11 March 2020, Microsoft shipped a fix for CVE-2020-0796, a wormable remote code execution flaw in how Windows 10 and Windows Server handle compressed SMBv3 packets. An attacker could send a specially crafted compressed packet and trigger a buffer overflow before authentication, exactly the class of bug security people fear could be chained into self-spreading malware. Researchers named it SMBGhost, published proof-of-concepts within days, demonstrated local privilege escalation chains, and Microsoft followed with an out-of-band patch update on 12 March. This technical retrospective covers the flaw mechanics, the compression workaround, the patch wave, and why the wormable nightmare never fully materialized.

Continue ReadingSMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3
>