{
  "id": "cve-2020-0796",
  "cveID": "CVE-2020-0796",
  "vendor": "Microsoft",
  "product": "SMBv3",
  "vulnerabilityName": "Microsoft SMBv3 Remote Code Execution Vulnerability",
  "shortDescription": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
  "requiredAction": "Apply updates per vendor instructions.",
  "dateAdded": "2022-02-10",
  "dueDate": "2022-08-10",
  "knownRansomware": true,
  "cwes": [
    "CWE-119"
  ],
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796",
  "sources": [
    {
      "label": "NVD",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796"
    },
    {
      "label": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    },
    {
      "label": "nvd.nist.gov",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-0796"
    }
  ],
  "cvss": {
    "score": 10,
    "severity": "CRITICAL",
    "version": "3.1",
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
  },
  "epss": {
    "score": 0.9981,
    "percentile": 0.99958
  },
  "timeline": [
    {
      "date": "2022-02-10",
      "event": "Added to the CISA KEV catalog"
    },
    {
      "date": "2022-08-10",
      "event": "CISA remediation due date (BOD 22-01)"
    }
  ],
  "status": "past due"
}