CVE-2020-0796

ENISA EUVD: EUVD-2020-2283 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 7 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.42%
probability
This CVE has a 94.42% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
10.0
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

Attack Intelligence

Exploits & PoC

ly4k/SMBGhost

Scanner for CVE-2020-0796 - SMBv3 RCE

717
jamf/CVE-2020-0796-RCE-POC

CVE-2020-0796 Remote Code Execution POC

575
Barriuso/SMBGhost_AutomateExploitation

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection

344
eerykitty/CVE-2020-0796-PoC

PoC for triggering buffer overflow via CVE-2020-0796

332
jamf/CVE-2020-0796-LPE-POC

CVE-2020-0796 Local Privilege Escalation POC

245
jiansiting/CVE-2020-0796

PoC CVE-2020-0796 — jiansiting/CVE-2020-0796

64
ioncodes/SMBGhost

Scanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE

58
7 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.42%
CVSS v3.1 10.0
Mentions 7
Last Seen Mar 16, 2020

CNA Information

Analyst Note

CVE-2020-0796 is the critical SMBv3 RCE vulnerability (WinRAT/CVE-2020-0796) publicly exploited in the wild in March 2020 before patches were widely available. CERT-EU advisory confirms active exploitation. Microsoft released emergency patches on March 12, 2020, the same day the vulnerability became public knowledge, indicating zero-day exploitation preceded patch availability.

Threat Actors 8

Cobalt
apt_group Financial crime 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
Earth Lamia
apt_group Information theft and espionage 🇨🇳 CN
Dalbit
apt_group Information theft and espionage 🇨🇳 CN
PhantomCore
apt_group 🇷🇺 RU
TA410
apt_group Information theft and espionage 🇨🇳 CN
Witchetty
apt_group 🇨🇳 CN

Triage Info

Decided atMar 05, 2026