vendor:
Windows 10
by:
Unknown
10
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Windows 10
Affected Version From: Windows 10 version 1903
Affected Version To: Windows 10 version 1909
Patch Exists: NO
Related CWE: CVE-2020-0796
CPE: o:microsoft:windows_10:1903 and cpe:/o:microsoft:windows_10:1909
Platforms Tested:
2020
CVE-2020-0796 PoC aka CoronaBlue aka SMBGhost
This script connects to the target host, and compresses the authentication request with a bad offset field set in the transformation header, causing the decompressor to buffer overflow and crash the target.
Mitigation:
Apply the latest security patches provided by the vendor.