CERT-EU published "Security Advisory 2020-014 - SMBv3 – Critical Remote Code Execution Vulnerability": media.cert.europa.eu/static/Securit… Basically currently it's a collection of already public info, workaround, etc...
MS added an update to their advisory (x.com/malwrhuntertea…) to clarify that "the vulnerability exists in a new feature that was added to Windows 10 version 1903. Older versions of Windows do not support SMBv3.1.1 compression."
MS released a patch: portal.msrc.microsoft.com/en-US/security… Now everyone can decide if they want to install it as soon as possible, or wait some time (with workarounds in place, of course) and see if it only patches the vulnerability or makes any problems (you know, we are talking about MS)...
Important details from
@SophosLabs. And spam is only one way. Think about hacked websites... Or even websites only created for this purpose, then linked to in different places. But of course, first a working exploit is needed...
