I’ve been sitting on pins and needles wondering when an in-the-wild exploit for the just-patched SMBv3 security hole might appear. Looks like it’s muc
[See the full post at: CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
Home » Forums » Newsletter and Homepage topics » CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
- This topic has 5 replies, 5 voices, and was last updated 5 years, 2 months ago.
AuthorTopicViewing 4 reply threadsAuthorReplies-
Seff
AskWoody Plus -
Mr. Natural
AskWoody Lounger -
anonymous
GuestMarch 13, 2020 at 6:22 pm #2190544If you run an SMB server, then you don’t need to patch, you just need to disable compression.
KASLR makes it much harder for unsophisticated attackers to execute code, but a denial of service exploit causing a computer to crash would not need to defeat KASLR and could be accomplished by anyone.
KASLR is not perfect protection: Every time you see an “Information Disclosure Vulnerability” listed as “2 – Exploitation Less Likely” in a Microsoft Security Guidance (there are TONS of these fixed every security update), that is potentially information that can be used to defeat KASLR.
If you read Google Project Zero, they make bypassing KASLR look easy, all the time. It may deter script kiddies, but it’s not gonna deter serious adversaries.
Luckily you don’t need to update to mitigate this. Disable compression on any SMB servers, if you have any 1903 or 1909 servers. If you have vulnerable servers, you should consider whether, in the future, you would be better served with an OS that is older, more stable, and supported for longer (Server 2019 is based on 1809 and not vulnerable).
You shouldn’t be hesitant to disable compression. After all, compression is a new feature only available since 2019. Disabling compression is more like uninstalling a bad feature patch than installing a new security patch.
This should be much less of a problem on clients, because your users should be smart enough to not connect to random SMB shares.
1 user thanked author for this post.
-
anonymous
GuestMarch 13, 2020 at 6:26 pm #2190546Kevin seems to be downplaying this solely from the Server side which may be the case.
However, according to the CVE:
“To exploit the vulnerability against a client, an unauthenticated attacker would need to configure a malicious SMBv3 server and convince a user to connect to it.”
While the “client” mentioned could only be a W10 PC at 1903 or 1909 that is unpatched, it would certainly suggest a much larger target group than those Kevin alludes to.
1 user thanked author for this post.
-
Alex5723
AskWoody PlusMarch 14, 2020 at 3:13 am #2190639Got this mail from Microsoft this morning :
The following CVE has undergone a minor revision increment:
* CVE-2020-0796
Revision Information:
=====================– CVE-2020-0796 | Windows SMBv3 Client/Server Remote Code Execution Vulnerability
– https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796– Reason for Revision: The following revisions have been made: 1. Added an FAQ to
clarify that only a Server Core installation is available for Windows Server,
version 1903 and Windows Server, version 1909. 2. In the Workarounds, added Note
number 3 to state that SMB Compression is not yet used by Windows or Windows Server,
and disabling SMB Compression has no negative performance impact. These are
informational changes only.
– Originally posted: March 12, 2020
– Updated: March 13, 2020
– Aggregate CVE Severity Rating: Critical
– Version: 1.1
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
7 minutes ago -
Stay connected anywhere
by
Peter Deegan
8 hours, 56 minutes ago -
Copilot, under the table
by
Will Fastie
1 hour, 13 minutes ago -
The Windows experience
by
Will Fastie
5 hours, 43 minutes ago -
A tale of two operating systems
by
Susan Bradley
1 hour, 34 minutes ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
11 hours, 3 minutes ago -
Where’s the cache today?
by
Up2you2
1 day, 2 hours ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
19 hours, 9 minutes ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
10 hours, 7 minutes ago -
Blocking Search (on task bar) from going to web
by
HenryW
1 day, 3 hours ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
1 day, 19 hours ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
1 day, 19 hours ago -
regarding april update and may update
by
heybengbeng
1 day, 21 hours ago -
MS Passkey
by
pmruzicka
23 hours, 9 minutes ago -
Can’t make Opera my default browser
by
bmeacham
2 days, 4 hours ago -
*Some settings are managed by your organization
by
rlowe44
1 day, 15 hours ago -
Formatting of “Forward”ed e-mails
by
Scott Mills
2 days, 3 hours ago -
SmartSwitch PC Updates will only be supported through the MS Store Going Forward
by
PL1
2 days, 23 hours ago -
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
3 days, 8 hours ago -
AI slop
by
Susan Bradley
1 day, 2 hours ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
3 days, 9 hours ago -
Two blank icons
by
CR2
17 hours, 57 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
19 hours, 55 minutes ago -
End of 10
by
Alex5723
3 days, 21 hours ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
2 days, 19 hours ago -
test post
by
gtd12345
4 days, 3 hours ago -
Privacy and the Real ID
by
Susan Bradley
3 days, 17 hours ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
1 day, 19 hours ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
4 days, 7 hours ago -
Upgrading from Win 10
by
WSjcgc50
2 days, 19 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.