CVE-2020-1206 is an information disclosure vulnerability in the Server Message Block 3.1.1 (SMBv3) protocol affecting Microsoft Windows 10 and Windows Server 2016. This flaw allows an unauthenticated attacker to remotely disclose sensitive information with high confidentiality impact, requiring no user interaction. While not listed on the KEV catalog, its high FAUCET Risk Score and significant community discussion, including a writeup detailing a chain with SMBGhost, indicate considerable interest. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not currently considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1909CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* | ||
1909CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.