
Researchers at Ricerca Security have discovered and demonstrated a vulnerability in Windows 10, dubbed CVE-2020-0796, which allows remote access to an attacker.
The vulnerability, also known as SMBGhost, was discovered in the Microsoft Server Message Block 3.1.1 (SMBv3) network communication protocol and only affects systems running Windows 10, version 1903 and 1909, as well as Server Core installations of Windows Server, versions 1903 and 1909.
Despite Microsoft having decided not to disclose the vulnerability and not issue a security advisory, some information about SMBGhost was leaked during last month's Patch Tuesday by various security vendors that are part of the company's Active Protections Program.
"An attacker who successfully exploited the vulnerability could gain code execution on the target server or client," Microsoft explains
Following the release of several Proof-of-Concepts (PoC) exploits, including a denial-of-service exploit developed by Kryptos Logic security researcher Marcus Hutchins, Microsoft released security for all affected platforms on March 12.
"However, although there have already been many public reports and PoCs for LPE (Local Privilege Escalation), none of them have shown that an RCE is actually possible so far," the Ricerca Security researchers said.
If patching all vulnerable systems wasn't urgent enough by now, Ricerca Security yesterday revealed a PoC RCE exploit for SMBGhost, with all the technical details behind it.
For now, however, Ricerca Security has decided not to publicly share the RCE PoC exploit to avoid the risk of it falling into the wrong hands.
Researchers at security firm Kryptos Logic have discovered approximately 48,000 Windows 10 hosts that are vulnerable to attacks targeting the SMBGhost vulnerability. If you haven't yet patched your Windows 10 systems against CVE-2020-0796, you should do so as soon as possible to block potential attacks.
