Yesterday, when Microsoft released its regular Patch Tuesday fixes, Cisco Talos and Fortinet inadvertently(?) also published information about CVE-2020-0796, a “wormable” vulnerability in the Microsoft Server Message Block (SMB) protocol that has yet to be fixed. Cisco Talos has since removed the entry but, a few hours later, Microsoft published an advisory offering more information and workarounds to be implemented until a fix is made available. About CVE-2020-0796 CVE-2020-0796 is a remote code execution vulnerability … More
The post Wormable Windows SMBv3 RCE flaw leaked, but not patched appeared first on Help Net Security.