What happened
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
Affected versions
SMBv3: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 48216Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)eerykitty2020-03-14VerifiedExploit-DB 48267Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege EscalationDaniel García Gutiérrez2020-03-30VerifiedExploit-DB 48537Microsoft Windows - 'SMBGhost' Remote Code Executionchompie13372020-06-02VerifiedSploitusSMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.KitPloit2026-08-24T16:34:43Candidatekitploit.comSMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.ru2026-08-24T16:34:43CandidatePoC-in-GitHub · k8gege/PyLadonLadon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894★ 52k8gege2019-11-19CandidatePoC-in-GitHub · 0x25bit/CVE-2020-0796-PoCWeaponized PoC for SMBv3 TCP codec/compression vulnerability★ 180x25bit2020-03-10CandidatePoC-in-GitHub · technion/DisableSMBCompressionCVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates★ 9technion2020-03-11CandidatePoC-in-GitHub · T13nn3s/CVE-2020-0796Powershell SMBv3 Compression checker★ 28T13nn3s2020-03-11CandidatePoC-in-GitHub · ly4k/SMBGhostScanner for CVE-2020-0796 - SMBv3 RCE★ 722ly4k2020-03-11CandidatePoC-in-GitHub · joaozietolie/CVE-2020-0796-CheckerScript that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)★ 14joaozietolie2020-03-11CandidatePoC-in-GitHub · ButrintKomoni/cve-2020-0796Identifying and Mitigating the CVE-2020–0796 flaw in the fly★ 17ButrintKomoni2020-03-11CandidatePoC-in-GitHub · dickens88/cve-2020-0796-scannerThis project is used for scanning cve-2020-0796 SMB vulnerability★ 14dickens882020-03-12CandidatePoC-in-GitHub · kn6869610/CVE-2020-0796★ 0kn68696102020-03-12CandidatePoC-in-GitHub · awareseven/eternalghosttestThis repository contains a test case for CVE-2020-0796★ 1awareseven2020-03-12CandidatePoC-in-GitHub · xax007/CVE-2020-0796-ScannerCVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner★ 0xax0072020-03-12CandidatePoC-in-GitHub · Dhoomralochana/Scanners-for-CVE-2020-0796-TestingScanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)★ 1Dhoomralochana2020-03-12CandidatePoC-in-GitHub · UraSecTeam/smbeeCheck system is vulnerable CVE-2020-0796 (SMB v3)★ 0UraSecTeam2020-03-12CandidatePoC-in-GitHub · netscylla/SMBGhostSMBGhost (CVE-2020-0796) threaded scanner★ 1netscylla2020-03-12CandidatePoC-in-GitHub · eerykitty/CVE-2020-0796-PoCPoC for triggering buffer overflow via CVE-2020-0796★ 331eerykitty2020-03-12CandidatePoC-in-GitHub · wneessen/SMBCompScanScanner script to identify hosts vulnerable to CVE-2020-0796★ 4wneessen2020-03-12CandidatePoC-in-GitHub · ioncodes/SMBGhostScanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE★ 57ioncodes2020-03-12CandidatePoC-in-GitHub · laolisafe/CVE-2020-0796SMBv3 RCE vulnerability in SMBv3★ 2laolisafe2020-03-12CandidatePoC-in-GitHub · gabimarti/SMBScannerMultithread SMB scanner to check CVE-2020-0796 for SMB v3.11★ 19gabimarti2020-03-12CandidatePoC-in-GitHub · Almorabea/SMBGhost-WorkaroundApplierThis script will apply the workaround for the vulnerability CVE-2020-0796 for the SMBv3 unauthenticated RCE★ 0Almorabea2020-03-12CandidatePoC-in-GitHub · vysecurity/CVE-2020-0796CVE-2020-0796 - Working PoC - 20200313★ 5vysecurity2020-03-13CandidatePoC-in-GitHub · BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)★ 1BinaryShadow942020-03-13CandidatePoC-in-GitHub · w1ld3r/SMBGhost_ScannerAdvanced scanner for CVE-2020-0796 - SMBv3 RCE★ 14w1ld3r2020-03-14CandidatePoC-in-GitHub · wsfengfan/CVE-2020-0796CVE-2020-0796 Python POC buffer overflow★ 0wsfengfan2020-03-14CandidatePoC-in-GitHub · GuoKerS/aioScan_CVE-2020-0796基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。★ 15GuoKerS2020-03-14CandidatePoC-in-GitHub · jiansiting/CVE-2020-0796-ScannerCVE-2020-0796-Scanner★ 9jiansiting2020-03-15CandidatePoC-in-GitHub · maxpl0it/Unauthenticated-CVE-2020-0796-PoCAn unauthenticated PoC for CVE-2020-0796★ 22maxpl0it2020-03-15CandidatePoC-in-GitHub · ran-sama/CVE-2020-0796Lightweight PoC and Scanner for CVE-2020-0796 without authentication.★ 1ran-sama2020-03-16CandidatePoC-in-GitHub · sujitawake/smbghostCVE-2020-0796_CoronaBlue_SMBGhost★ 3sujitawake2020-03-16CandidatePoC-in-GitHub · julixsalas/CVE-2020-0796Scanner for CVE-2020-0796★ 1julixsalas2020-03-16CandidatePoC-in-GitHub · cory-zajicek/CVE-2020-0796-DoSDoS PoC for CVE-2020-0796 (SMBGhost)★ 1cory-zajicek2020-03-21CandidatePoC-in-GitHub · tripledd/cve-2020-0796-vuln★ 0tripledd2020-03-30CandidatePoC-in-GitHub · danigargu/CVE-2020-0796CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost★ 1359danigargu2020-03-30CandidatePoC-in-GitHub · jamf/CVE-2020-0796-LPE-POCCVE-2020-0796 Local Privilege Escalation POC★ 244jamf2020-03-30CandidatePoC-in-GitHub · TinToSer/CVE-2020-0796-LPESMBGHOST local privilege escalation★ 2TinToSer2020-03-31CandidatePoC-in-GitHub · f1tz/CVE-2020-0796-LPE-EXPWindows SMBv3 LPE exploit 已编译版★ 17f1tz2020-03-31CandidatePoC-in-GitHub · tango-j/CVE-2020-0796Coronablue exploit★ 4tango-j2020-03-31CandidatePoC-in-GitHub · jiansiting/CVE-2020-0796★ 65jiansiting2020-04-01CandidatePoC-in-GitHub · eastmountyxz/CVE-2020-0796-SMB该资源为CVE-2020-0796漏洞复现,包括Python版本和C++版本。主要是集合了github大神们的资源,希望您喜欢~★ 33eastmountyxz2020-04-02CandidatePoC-in-GitHub · LabDookhtegan/CVE-2020-0796-EXPCVE-2020-0796-EXP★ 1LabDookhtegan2020-04-02CandidatePoC-in-GitHub · Rvn0xsy/CVE_2020_0796_CNACobalt Strike AggressorScripts CVE-2020-0796★ 75Rvn0xsy2020-04-06CandidatePoC-in-GitHub · 0xeb-bp/cve-2020-0796CVE-2020-0796 (SMBGhost) LPE★ 70xeb-bp2020-04-07CandidatePoC-in-GitHub · intelliroot-tech/cve-2020-0796-ScannerThis tool helps scan large subnets for cve-2020-0796 vulnerable systems★ 0intelliroot-tech2020-04-14CandidatePoC-in-GitHub · jamf/CVE-2020-0796-RCE-POCCVE-2020-0796 Remote Code Execution POC★ 571jamf2020-04-20CandidatePoC-in-GitHub · thelostworldFree/CVE-2020-0796PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)★ 11thelostworldFree2020-04-22CandidatePoC-in-GitHub · bacth0san96/SMBGhostScannerSMBGhost CVE-2020-0796★ 0bacth0san962020-05-12CandidatePoC-in-GitHub · halsten/CVE-2020-0796★ 0halsten2020-05-28CandidatePoC-in-GitHub · ysyyrps123/CVE-2020-0796-expCVE-2020-0796-exp★ 0ysyyrps1232020-06-02CandidatePoC-in-GitHub · exp-sky/CVE-2020-0796SMBv3 Ghost (CVE-2020-0796) Vulnerability★ 3exp-sky2020-06-09CandidatePoC-in-GitHub · Barriuso/SMBGhost_AutomateExploitationSMBGhost (CVE-2020-0796) Automate Exploitation and Detection★ 357Barriuso2020-06-10CandidatePoC-in-GitHub · 1060275195/SMBGhost批量测试CVE-2020-0796 - SMBv3 RCE★ 010602751952020-06-11CandidatePoC-in-GitHub · Almorabea/SMBGhost-LPE-Metasploit-ModuleThis is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework★ 20Almorabea2020-06-19CandidatePoC-in-GitHub · jamf/SMBGhost-SMBleed-scannerSMBGhost (CVE-2020-0796) and SMBleed (CVE-2020-1206) Scanner★ 44jamf2020-07-06CandidatePoC-in-GitHub · rsmudge/CVE-2020-0796-BOF★ 70rsmudge2020-09-17CandidatePoC-in-GitHub · codewithpradhan/SMBGhost-CVE-2020-0796-To crash Windows-10 easily★ 3codewithpradhan2020-09-28CandidatePoC-in-GitHub · AaronCaiii/CVE-2020-0796-POCCVE-2020-0796-POC★ 0AaronCaiii2020-11-06CandidatePoC-in-GitHub · datntsec/CVE-2020-0796★ 1datntsec2020-11-10CandidatePoC-in-GitHub · MasterSploit/LPE---CVE-2020-0796★ 2MasterSploit2020-11-20CandidatePoC-in-GitHub · 1stPeak/CVE-2020-0796-Scanner★ 11stPeak2021-07-14CandidatePoC-in-GitHub · Anonimo501/SMBGhost_CVE-2020-0796_checker★ 2Anonimo5012021-09-04CandidatePoC-in-GitHub · Opensitoo/cve-2020-0796★ 0Opensitoo2021-10-04CandidatePoC-in-GitHub · orangmuda/CVE-2020-0796Remote Code Execution POC for CVE-2020-0796★ 5orangmuda2021-10-09CandidatePoC-in-GitHub · Murasame-nc/CVE-2020-0796-LPE-POC★ 0Murasame-nc2021-10-09CandidatePoC-in-GitHub · F6JO/CVE-2020-0796-Batch-scanning批量扫描CVE-2020-0796★ 1F6JO2021-10-28CandidatePoC-in-GitHub · lisinan988/CVE-2020-0796-exp★ 0lisinan9882021-11-25CandidatePoC-in-GitHub · vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-Description of Exploit SMBGhost CVE-2020-0796★ 0vsai942022-03-28CandidatePoC-in-GitHub · arzuozkan/CVE-2020-0796CVE-2020-0796 explanation and researching vulnerability for term porject CENG325★ 1arzuozkan2022-06-07CandidatePoC-in-GitHub · SEHandler/CVE-2020-0796CVE-2020-0796★ 1SEHandler2022-11-09CandidatePoC-in-GitHub · krizzz07/CVE-2020-0796windows 10 SMB vulnerability★ 0krizzz072023-01-29CandidatePoC-in-GitHub · OldDream666/cve-2020-0796cve-2020-0796利用工具集★ 1OldDream6662023-02-28CandidatePoC-in-GitHub · dungnm24/CVE-2020-0796WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.★ 6dungnm242023-05-29CandidatePoC-in-GitHub · hungdnvp/POC-CVE-2020-0796★ 0hungdnvp2024-02-23CandidatePoC-in-GitHub · AdamSonov/smbGhostCVE-2020-0796This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)★ 1AdamSonov2024-03-04CandidatePoC-in-GitHub · z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-VulnerabilitiesThis repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.★ 0z3ena2024-08-12CandidatePoC-in-GitHub · bsec404/CVE-2020-0796★ 1bsec4042025-01-29CandidatePoC-in-GitHub · monjheta/CVE-2020-0796★ 0monjheta2025-02-26CandidatePoC-in-GitHub · cybermads/CVE-2020-0796★ 1cybermads2025-04-19CandidatePoC-in-GitHub · DannyRavi/nmap-scriptsnmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327★ 2DannyRavi2025-04-20CandidatePoC-in-GitHub · tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo★ 0tdevworks2025-05-17CandidatePoC-in-GitHub · maqeel-git/CVE-2020-0796★ 0maqeel-git2025-06-14CandidatePoC-in-GitHub · esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-★ 0esmwaSpyware2025-08-06CandidatePoC-in-GitHub · Jagadeesh7532/-CVE-2020-0796-SMBGhost-Windows-10-SMBv3-Remote-Code-Execution-VulnerabilityCVE-2020-0796 (SMBGhost) is a critical RCE vulnerability in Windows 10 SMBv3 protocol. It allows attackers to execute code remotely via crafted SMB packets, making it wormable. Affects Windows 10 v1903/v1909 and Server 2019. Exploit targets srv2.sys via buffer overflow★ 2Jagadeesh75322025-09-21CandidatePoC-in-GitHub · nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE★ 0nyambiblaise2025-12-30CandidatePoC-in-GitHub · thai1012/cve-2020-0796★ 0thai10122026-02-04CandidatePoC-in-GitHub · Justjeff211/conti-ransomware-writeupConducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe★ 0Justjeff2112026-03-27CandidatePoC-in-GitHub · p4ncontomat3/smbghostscanner for CVE-2020-0796★ 0p4ncontomat32026-06-26CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.