Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Request CVE-2020-0796 Windows SMBv3 Client/Server Remote Code Execution Vulnerability #198

Closed
hh-hunter opened this issue Nov 12, 2021 · 0 comments
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.

Comments

@hh-hunter
Copy link
Contributor

Hello,
I would like to start the implementation for a plugin that detects CVE-2020-0796,The vulnerability should be relatively new and have already been patched.

The vulnerability has been assigned a CVE ID (CVSS score >= 7.0), and the vulnerability has a HIGH or CRITICAL severity level: CVSS score: 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

The radius of impact of the vulnerability is very large, and the scope of impact is as follows:
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows Server, Version 1903 (Server Core installation)
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows Server, Version 1909 (Server Core installation)
This vulnerability can be exploited remotely without authentication and user interaction.
Since the vulnerability is a windows environment, docker cannot be built, but I can provide ISO images of related vulnerability versions and repaired versions, or very large virtual machine images.

Please let me know if this is within the scope of starting development.

@tooryx tooryx added Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. and removed PRP:Request labels Feb 1, 2024
@tooryx tooryx closed this as completed Jul 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.
Projects
None yet
Development

No branches or pull requests

3 participants