I’ve been sitting on pins and needles wondering when an in-the-wild exploit for the just-patched SMBv3 security hole might appear. Looks like it’s muc
[See the full post at: CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
Home » Forums » Newsletter and Homepage topics » CVE-2020-0796, the SMBv3 security hole, doesn’t pose an immediate threat
- This topic has 5 replies, 5 voices, and was last updated 5 years, 1 month ago.
AuthorTopicViewing 4 reply threadsAuthorReplies-
Seff
AskWoody Plus -
Mr. Natural
AskWoody Lounger -
anonymous
GuestMarch 13, 2020 at 6:22 pm #2190544If you run an SMB server, then you don’t need to patch, you just need to disable compression.
KASLR makes it much harder for unsophisticated attackers to execute code, but a denial of service exploit causing a computer to crash would not need to defeat KASLR and could be accomplished by anyone.
KASLR is not perfect protection: Every time you see an “Information Disclosure Vulnerability” listed as “2 – Exploitation Less Likely” in a Microsoft Security Guidance (there are TONS of these fixed every security update), that is potentially information that can be used to defeat KASLR.
If you read Google Project Zero, they make bypassing KASLR look easy, all the time. It may deter script kiddies, but it’s not gonna deter serious adversaries.
Luckily you don’t need to update to mitigate this. Disable compression on any SMB servers, if you have any 1903 or 1909 servers. If you have vulnerable servers, you should consider whether, in the future, you would be better served with an OS that is older, more stable, and supported for longer (Server 2019 is based on 1809 and not vulnerable).
You shouldn’t be hesitant to disable compression. After all, compression is a new feature only available since 2019. Disabling compression is more like uninstalling a bad feature patch than installing a new security patch.
This should be much less of a problem on clients, because your users should be smart enough to not connect to random SMB shares.
1 user thanked author for this post.
-
anonymous
GuestMarch 13, 2020 at 6:26 pm #2190546Kevin seems to be downplaying this solely from the Server side which may be the case.
However, according to the CVE:
“To exploit the vulnerability against a client, an unauthenticated attacker would need to configure a malicious SMBv3 server and convince a user to connect to it.”
While the “client” mentioned could only be a W10 PC at 1903 or 1909 that is unpatched, it would certainly suggest a much larger target group than those Kevin alludes to.
1 user thanked author for this post.
-
Alex5723
AskWoody PlusMarch 14, 2020 at 3:13 am #2190639Got this mail from Microsoft this morning :
The following CVE has undergone a minor revision increment:
* CVE-2020-0796
Revision Information:
=====================– CVE-2020-0796 | Windows SMBv3 Client/Server Remote Code Execution Vulnerability
– https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796– Reason for Revision: The following revisions have been made: 1. Added an FAQ to
clarify that only a Server Core installation is available for Windows Server,
version 1903 and Windows Server, version 1909. 2. In the Workarounds, added Note
number 3 to state that SMB Compression is not yet used by Windows or Windows Server,
and disabling SMB Compression has no negative performance impact. These are
informational changes only.
– Originally posted: March 12, 2020
– Updated: March 13, 2020
– Aggregate CVE Severity Rating: Critical
– Version: 1.1
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
7 hours, 42 minutes ago -
AI slop
by
Susan Bradley
6 hours, 52 minutes ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
8 hours, 58 minutes ago -
Two blank icons
by
CR2
15 hours, 28 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
17 hours, 52 minutes ago -
End of 10
by
Alex5723
20 hours, 33 minutes ago -
End Of 10 : Move to Linux
by
Alex5723
21 hours, 2 minutes ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
17 hours, 31 minutes ago -
test post
by
gtd12345
1 day, 2 hours ago -
Privacy and the Real ID
by
Susan Bradley
16 hours, 41 minutes ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
8 hours, 47 minutes ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
1 day, 6 hours ago -
Upgrading from Win 10
by
WSjcgc50
8 hours, 17 minutes ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
29 minutes ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
1 day, 22 hours ago -
The story of Windows Longhorn
by
Cybertooth
1 day, 10 hours ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
2 days ago -
Are manuals extinct?
by
Susan Bradley
12 hours, 1 minute ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
2 days, 9 hours ago -
Network Issue
by
Casey H
1 day, 20 hours ago -
Fedora Linux is now an official WSL distro
by
Alex5723
2 days, 21 hours ago -
May 2025 Office non-Security updates
by
PKCano
2 days, 22 hours ago -
Windows 10 filehistory including onedrive folder
by
Steve Bondy
3 days ago -
pages print on restart (Win 11 23H2)
by
cyraxote
2 days ago -
Windows 11 Insider Preview build 26200.5581 released to DEV
by
joep517
3 days, 2 hours ago -
Windows 11 Insider Preview build 26120.3950 (24H2) released to BETA
by
joep517
3 days, 2 hours ago -
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
3 days, 9 hours ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
1 hour, 30 minutes ago -
Asking Again here (New User and Fast change only backups)
by
thymej
3 days, 20 hours ago -
How much I spent on the Mac mini
by
Will Fastie
1 day, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.