Microsoft leaks information about ‘wormable’ flaw before releasing patch
Microsoft accidentally leaked information about a security update for a vulnerability, tracked as CVE-2020-0796, which reportedly should have been disclosed as part of Patch Tuesday. This is a ‘wormable’ pre-auth remote code execution vulnerability, caused by an error in the way the SMBv3 handles maliciously crafted compressed data packets. It can allow a remote and … Microsoft leaks information about ‘wormable’ flaw before releasing patch
