Threat Management, Malware, Network Security, Vulnerability Management

Attackers are using exploit code for SMBGhost bug, CISA warns

Functioning point-of-concept exploit code now exists for the highly critical "SMBGhost" bug that Microsoft last March patched in its Server Message Block 3.1.1 (SMBv3) protocol, and attackers are taking advantage, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned, citing open-source reports.

Designated CVE-2020-0796 and also known as EternalDarkness, the bug can result in a wormable remote code execution attack on a targeted SMB server or client. Microsoft on March 12 issued an out-of-band patch for the vulnerability after an apparent error in the Microsoft vulnerability disclosure process led to at least two cyber companies prematurely posting information about the flaw before Microsoft had the opportunity to publicly disclose the bug.

In addition to patching the vulnerability, CISA recommends that users employ a firewall to block SMB ports from the internet.

Various news sources have reported that a researcher with the Twitter handle "Chompie" has shared SMBGhost RCE exploit code publicly on GitHub. Back in April, the cybersecurity company Ricerca Security similarly made PoC code available.

BleepingComputer also reported that the cybersecurity company ZecOps has demonstrated how SMBGhost can be exploited for denial of service and local privilege escalation, and Kryptos Logic demoed a DoS exploit as well. It has also reported that cybercriminals already have been leveraging the bug to deliver the Ave Maria remote access trojan.

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.