MalwareHunterTeam (@malwrhunterteam) on X

X (formerly Twitter) ·

2 min read Original article ↗

user avatar

user avatar

And if it wouldn't be enough interesting, they just did this... 🤔

user avatar

And I was late to find, others was faster... So even if I would delete my tweet (when I saw the first reply saying it was deleted), it would be already late...

user avatar

user avatar

"Created: today Updated: yesterday Severity: maximum" What's going on? 🤔

user avatar

People started to ask, so adding it here too to get more visibility: "how to disable SMBv3 compression"?

user avatar

Can it get more strange than this? 🤔

user avatar

You know

@arekfurt

, for MS, "quality standards" are gone from some years ago already...

user avatar

You know how great is that there is recommendation to disable SMBv3 compression, but to find out how to do that people has to reverse files? 😫

user avatar

Some people wants to be cool and name it with including the word "corona" in it. We recommend to use SMBGhost name for it - SMB is obviously for what, Ghost because "it not exists".

user avatar

user avatar

user avatar

Also, finally they revealed the "official way" to disable SMBv3 compression:

user avatar

This. Just use the CVE ID, or if you want name, use the SMBGhost one and that's it...

user avatar

user avatar

Palo Alto also categorizes it as "critical" severity. But at least they have signatures too...

user avatar

user avatar

Also

@ET_Labs

has some coverage for it already:

user avatar

CERT-EU published "Security Advisory 2020-014 - SMBv3 – Critical Remote Code Execution Vulnerability": media.cert.europa.eu/static/Securit… Basically currently it's a collection of already public info, workaround, etc...

user avatar

user avatar

And seems Windows Defender already can catch some exploit attempts...

user avatar

MS added an update to their advisory (x.com/malwrhuntertea…) to clarify that "the vulnerability exists in a new feature that was added to Windows 10 version 1903. Older versions of Windows do not support SMBv3.1.1 compression."

user avatar

user avatar

48k vulnerable hosts that are accessible from the internet directly is not a few:

user avatar

MS released a patch: portal.msrc.microsoft.com/en-US/security… Now everyone can decide if they want to install it as soon as possible, or wait some time (with workarounds in place, of course) and see if it only patches the vulnerability or makes any problems (you know, we are talking about MS)...

user avatar

"Update ASAP or use the workaround"

user avatar

Important details from

@SophosLabs

. And spam is only one way. Think about hacked websites... Or even websites only created for this purpose, then linked to in different places. But of course, first a working exploit is needed...

user avatar

In past days, multiple crash PoC codes were made available for skids, so everyone patch or use the workaround...