Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Out-of-Band Windows Updates Patch Wormable SMB Vulnerability

Microsoft has released out-of-band updates for Windows to patch a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that has been described as “wormable.”

Microsoft has released out-of-band updates for Windows to patch a critical remote code execution vulnerability in Server Message Block 3.0 (SMBv3) that has been described as “wormable.”

The vulnerability, related to the way SMB 3.1.1 handles certain requests, can be exploited by an unauthenticated attacker to execute arbitrary code on SMB servers and clients.

In attacks aimed at SMB servers, the attacker needs to send specially crafted packets to the targeted system, and in the case of clients, the hacker has to convince the victim to connect to a malicious SMBv3 server.

The existence of the vulnerability was disclosed by Microsoft on Tuesday, when the company released its monthly security updates. At the time, Microsoft said it had been working on a patch and provided mitigation advice.

The flaw, discovered by Microsoft’s own researchers, is officially tracked as CVE-2020-0796 and some members of the cybersecurity industry have named it CoronaBlue and SMBGhost. The weakness impacts Windows 10 and Windows Server versions 1903 and 1909.

Microsoft has not disclosed too many technical details about the vulnerability and a patch was not available until now for analysis. However, researchers have still managed to create scanners for detecting vulnerable servers, and Kryptos Logic claims its experts developed a proof-of-concept (PoC) exploit that achieves a DoS condition.

Kryptos Logic says it has conducted an internet-wide scan for CVE-2020-0796 and identified roughly 48,000 vulnerable hosts.

Users who are unable to immediately apply the patch have been advised to disable SMBv3 compression by following the instructions provided by Microsoft.

Related: Attacks Targeting Recent Microsoft Exchange Flaw Ramping Up

Related: NSA Discloses Serious Windows Vulnerability to Microsoft

Related: Microsoft Patches RDS Vulnerability Allowing WannaCry-Like Attacks

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Malware & Threats

Microsoft plans to improve the protection of Office users by blocking XLL add-ins from the internet.

Vulnerabilities

Security researchers have observed an uptick in attacks targeting CVE-2021-35394, an RCE vulnerability in Realtek Jungle SDK.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Vulnerabilities

Several vulnerabilities have been patched in OpenText’s enterprise content management (ECM) product.