CVE-2020-1206
CVE-2020-1206
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 9.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Jun 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.
Affected products
Microsoft · Windows 10 Version 1903 for 32-bit SystemsMicrosoft · Windows 10 Version 1903 for ARM64-based SystemsMicrosoft · Windows 10 Version 1903 for x64-based SystemsMicrosoft · Windows 10 Version 1909 for 32-bit SystemsMicrosoft · Windows 10 Version 1909 for ARM64-based SystemsMicrosoft · Windows 10 Version 1909 for x64-based SystemsMicrosoft · Windows 10 Version 2004 for 32-bit SystemsMicrosoft · Windows 10 Version 2004 for ARM64-based SystemsMicrosoft · Windows 10 Version 2004 for x64-based SystemsMicrosoft · Windows Server, version 1903 (Server Core installation)Microsoft · Windows Server, version 1909 (Server Core installation)Microsoft · Windows Server, version 2004 (Server Core installation)