I’ve been sitting on pins and needles wondering when an in-the-wild exploit for the just-patched SMBv3 security hole might appear. Looks like it’s muc
[See the full post at: CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
Home » Forums » Newsletter and Homepage topics » CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
- This topic has 5 replies, 5 voices, and was last updated 3 years, 6 months ago.
AuthorTopicwoody
ManagerViewing 4 reply threadsAuthorReplies-
Seff
AskWoody Plus -
Mr. Natural
AskWoody Lounger -
anonymous
GuestIf you run an SMB server, then you don’t need to patch, you just need to disable compression.
KASLR makes it much harder for unsophisticated attackers to execute code, but a denial of service exploit causing a computer to crash would not need to defeat KASLR and could be accomplished by anyone.
KASLR is not perfect protection: Every time you see an “Information Disclosure Vulnerability” listed as “2 – Exploitation Less Likely” in a Microsoft Security Guidance (there are TONS of these fixed every security update), that is potentially information that can be used to defeat KASLR.
If you read Google Project Zero, they make bypassing KASLR look easy, all the time. It may deter script kiddies, but it’s not gonna deter serious adversaries.
Luckily you don’t need to update to mitigate this. Disable compression on any SMB servers, if you have any 1903 or 1909 servers. If you have vulnerable servers, you should consider whether, in the future, you would be better served with an OS that is older, more stable, and supported for longer (Server 2019 is based on 1809 and not vulnerable).
You shouldn’t be hesitant to disable compression. After all, compression is a new feature only available since 2019. Disabling compression is more like uninstalling a bad feature patch than installing a new security patch.
This should be much less of a problem on clients, because your users should be smart enough to not connect to random SMB shares.
1 user thanked author for this post.
-
anonymous
GuestKevin seems to be downplaying this solely from the Server side which may be the case.
However, according to the CVE:
“To exploit the vulnerability against a client, an unauthenticated attacker would need to configure a malicious SMBv3 server and convince a user to connect to it.”
While the “client” mentioned could only be a W10 PC at 1903 or 1909 that is unpatched, it would certainly suggest a much larger target group than those Kevin alludes to.
1 user thanked author for this post.
-
Alex5723
AskWoody PlusGot this mail from Microsoft this morning :
The following CVE has undergone a minor revision increment:
* CVE-2020-0796
Revision Information:
=====================– CVE-2020-0796 | Windows SMBv3 Client/Server Remote Code Execution Vulnerability
– https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796– Reason for Revision: The following revisions have been made: 1. Added an FAQ to
clarify that only a Server Core installation is available for Windows Server,
version 1903 and Windows Server, version 1909. 2. In the Workarounds, added Note
number 3 to state that SMB Compression is not yet used by Windows or Windows Server,
and disabling SMB Compression has no negative performance impact. These are
informational changes only.
– Originally posted: March 12, 2020
– Updated: March 13, 2020
– Aggregate CVE Severity Rating: Critical
– Version: 1.1
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Long Live the Red Envelope Era | Farewell to DVDs | Netflix
by
Alex5723
18 hours, 14 minutes ago -
Faststone Image Viewer updates
by
Alex5723
19 hours, 58 minutes ago -
Malicious ad served inside Bing’s AI chatbot
by
Alex5723
20 hours, 1 minute ago -
win10 pro 22H2 current minus 1 mo,to, win11. suggestions…
by
krism
8 hours, 28 minutes ago -
Microsoft entered negotiations to sell Bing to Apple in 2020
by
Alex5723
1 day, 5 hours ago -
X CEO shows her iPhone’s Home Screen – and X isn’t there
by
Alex5723
1 day, 6 hours ago -
Keeping an older Mac secure
by
Susan Bradley
1 day, 6 hours ago -
Thunderbird – problem ”setting up existing email address”
by
stajourneyman
1 day, 6 hours ago -
Windows 11 Insider Preview build 23555 released to DEV
by
joep517
1 day, 17 hours ago -
Something didn’t go as planned KB5030310, KB 5030219
by
Donald Wyllie
6 hours, 53 minutes ago -
“Enhanced” search box
by
WSraysig
1 day, 18 hours ago -
Windows Ends Installation Path for Free Windows 7/8 Upgrade
by
Alex5723
1 day, 19 hours ago -
Icon text drop shadows latest Win 11 update
by
kenlcarter50
1 day, 13 hours ago -
Group Policy to change context menu to Win10 version?
by
HATech19
1 day, 20 hours ago -
You can no longer activate newer Windows 11 builds with Windows 7/8/8.1 keys
by
joep517
19 hours, 53 minutes ago -
Reddit is removing the option to prevent Reddit from tracking ..
by
Alex5723
2 days, 4 hours ago -
Vivaldi for iOS and iPadOS released
by
Alex5723
2 days, 4 hours ago -
Windows 11 attempted update to 22H2 results in Error Code 0x8024001e
by
Tiernan
1 day, 18 hours ago -
lock screen goes black after ~ 25-30 secs.
by
krism
1 day, 13 hours ago -
Need File Location Which Lists Default Apps Used
by
HARLEYMAN124
13 hours, 36 minutes ago -
Canadian’s identify alternative tape that prolongs life of laptop batteries
by
Kathy Stevens
2 days, 15 hours ago -
Browswers and Windows 11
by
WSG
2 days, 15 hours ago -
Advice on whether to upgrade to Windows 11
by
millerah
2 days, 15 hours ago -
Linuxmint LMDE 6 Officially Released
by
Microfix
1 day, 18 hours ago -
Edge browser – ad quality concern
by
doriel
14 hours, 35 minutes ago -
Strange problem after upgrade from Win10Pro 22H2 to Win11Pro 22H2
by
JohnH
2 days, 6 hours ago -
Return Full Context Menus to File Explorer
by
RetiredGeek
1 day, 20 hours ago -
Unusual Activity on Startup
by
Kenneth Stephens
18 hours, 34 minutes ago -
Windows Backup – incremental possible?
by
colin_thames
3 days, 15 hours ago -
New HD addition??
by
weendoggy
3 days, 6 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.