Executive brief
A remote code execution vulnerability exists in the Microsoft Server Message Block 3.1.1 (SMBv3) protocol due to improper handling of certain requests. An unauthenticated attacker could exploit this to execute arbitrary code on a target SMB server or client.
Affected products
- Microsoft Windows 10 1903, 1909
- Microsoft Windows Server 1903, 1909
Timeline
- 2020-03-12: advisory: Initial Microsoft advisory published
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-10: disclosed: Publicly disclosed date per NVD record