Skip to main content
Mallory
High

SMBleed

IdentifiersCVE-2020-1206CWE-200

CVE-2020-1206, also known as SMBleed, is a remote information disclosure vulnerability in Microsoft SMBv3 / SMB 3.1.1. According to the provided content, the flaw exists in the way the SMBv3 protocol handles certain requests, and is associated with the SMB server driver function Srv2DecompressData. Successful exploitation can cause a vulnerable Windows SMB client or server to leak kernel memory contents. The content also notes this issue was discussed as related to SMBGhost (CVE-2020-0796), with public reporting describing SMBleed as usable for memory disclosure and ASLR bypass in chained exploitation scenarios.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows remote disclosure of sensitive memory from the target system, specifically kernel memory information per the provided advisory context. This can expose pointers and other in-memory data useful for defeating exploit mitigations such as ASLR, improving exploit reliability for other vulnerabilities, and revealing sensitive system state. The content specifically notes SMBleed can be chained with CVE-2020-0796 (SMBGhost) to support more stable remote code execution attacks.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce SMB exposure to untrusted networks, restrict access to SMB services to only necessary hosts, and limit writable shares and unnecessary SMB access paths. Because the content indicates exploitation may involve credentials and a writable share, tightening share permissions and minimizing authenticated SMB access can reduce risk. Monitor for anomalous SMB activity and treat CVE-2020-1206 as especially high risk when combined with SMBGhost (CVE-2020-0796).

Remediation

Patch, then assume compromise.

Apply Microsoft's security updates for affected Windows versions. The provided content states patches were released and specifically references installing the latest Microsoft updates for affected Windows 10 versions, including builds around versions 1903, 1909, and 2004 that were vulnerable prior to the relevant KB updates. Use the official Microsoft security guidance and ensure SMBv3-capable systems are fully patched.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.

VALID 0 / 2 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationWindows 10operating_system
Microsoft CorporationWindows Server 2016operating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.