SMBv3 Compression Buffer Overflow

zetlyn/cve-metasploit exploit cve CVE-2020-0796 known 2020-03-13

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2020_0796_smbghost.rb

Properties

platformWindows
receipt
Source
Metasploit exploit modules
Its words
Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 20:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Daniel García Gutiérrez",
    "Manuel Blanco Parajón",
    "Spencer McIntyre"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to\n            execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself\n            before injecting a payload into winlogon.exe.",
  "disclosure_date": "2020-03-13",
  "fullname": "exploit/windows/local/cve_2020_0796_smbghost",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:46 +0000",
  "name": "SMBv3 Compression Buffer Overflow",
  "needs_cleanup": null,
  "notes": {
    "AKA": [
      "SMBGhost",
      "CoronaBlue"
    ],
    "RelatedModules": [
      "exploit/windows/smb/cve_2020_0796_smbghost"
    ],
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-os-restarts"
    ]
  },
  "path": "/modules/exploits/windows/local/cve_2020_0796_smbghost.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 400,
  "ref_name": "windows/local/cve_2020_0796_smbghost",
  "references": [
    "CVE-2020-0796",
    "URL-https://github.com/danigargu/CVE-2020-0796",
    "URL-https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005"
  ],
  "rport": null,
  "session_types": [
    "meterpreter"
  ],
  "targets": [
    "Windows 10 v1903-1909 x64"
  ],
  "type": "exploit"
}
rank400
Good. A default target, reliable against the common configuration.
receipt
Source
Metasploit exploit modules
Its words
400
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 20:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Daniel García Gutiérrez",
    "Manuel Blanco Parajón",
    "Spencer McIntyre"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to\n            execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself\n            before injecting a payload into winlogon.exe.",
  "disclosure_date": "2020-03-13",
  "fullname": "exploit/windows/local/cve_2020_0796_smbghost",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:46 +0000",
  "name": "SMBv3 Compression Buffer Overflow",
  "needs_cleanup": null,
  "notes": {
    "AKA": [
      "SMBGhost",
      "CoronaBlue"
    ],
    "RelatedModules": [
      "exploit/windows/smb/cve_2020_0796_smbghost"
    ],
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-os-restarts"
    ]
  },
  "path": "/modules/exploits/windows/local/cve_2020_0796_smbghost.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 400,
  "ref_name": "windows/local/cve_2020_0796_smbghost",
  "references": [
    "CVE-2020-0796",
    "URL-https://github.com/danigargu/CVE-2020-0796",
    "URL-https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005"
  ],
  "rport": null,
  "session_types": [
    "meterpreter"
  ],
  "targets": [
    "Windows 10 v1903-1909 x64"
  ],
  "type": "exploit"
}

Text

A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself before injecting a payload into winlogon.exe.