HomeSecuritySecurity researchers exploited SMBGhost RCE vulnerability

Security researchers exploited SMBGhost RCE vulnerability

SMBGhost

Researchers at Ricerca Security have discovered and demonstrated a vulnerability in Windows 10, dubbed CVE-2020-0796, which allows remote access to an attacker.

The vulnerability, also known as SMBGhost, was discovered in the Microsoft Server Message Block 3.1.1 (SMBv3) network communication protocol and only affects systems running Windows 10, version 1903 and 1909, as well as Server Core installations of Windows Server, versions 1903 and 1909.

Despite Microsoft having decided not to disclose the vulnerability and not issue a security advisory, some information about SMBGhost was leaked during last month's Patch Tuesday by various security vendors that are part of the company's Active Protections Program.

"An attacker who successfully exploited the vulnerability could gain code execution on the target server or client," Microsoft explains

Following the release of several Proof-of-Concepts (PoC) exploits, including a denial-of-service exploit developed by Kryptos Logic security researcher Marcus Hutchins, Microsoft released security for all affected platforms on March 12.

"However, although there have already been many public reports and PoCs for LPE (Local Privilege Escalation), none of them have shown that an RCE is actually possible so far," the Ricerca Security researchers said.

If patching all vulnerable systems wasn't urgent enough by now, Ricerca Security yesterday revealed a PoC RCE exploit for SMBGhost, with all the technical details behind it.

For now, however, Ricerca Security has decided not to publicly share the RCE PoC exploit to avoid the risk of it falling into the wrong hands.

Researchers at security firm Kryptos Logic have discovered approximately 48,000 Windows 10 hosts that are vulnerable to attacks targeting the SMBGhost vulnerability. If you haven't yet patched your Windows 10 systems against CVE-2020-0796, you should do so as soon as possible to block potential attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS