Security News > 2020 > March > Users Complain About Windows Update That Patches SMBGhost Vulnerability

Users Complain About Windows Update That Patches SMBGhost Vulnerability
2020-03-17 12:59

Some users have complained that the Windows security update released recently by Microsoft to patch a wormable vulnerability related to Server Message Block 3.0 is causing problems.

Microsoft released an out-of-band update for Windows 10 and Windows Server on March 12 to fix CVE-2020-0796, a vulnerability that can allow an unauthenticated attacker to execute arbitrary code on SMB servers and clients.

Some users have complained on Reddit, Microsoft forums and other websites that the update, KB4551762, has been causing problems.

SecurityWeek has reached out to Microsoft to find out what is being done to address these issues and will update this article if the company responds.

Since the flaw is likely to be exploited in attacks in the upcoming period, users have been advised to install the available updates as soon as possible, or at least apply mitigations.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/KPu_3oxHGjE/users-complain-about-windows-update-patches-smbghost-vulnerability

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-03-12 CVE-2020-0796 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Windows 10 and Windows Server 2016
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-119
7.5