SMBGhost

SMBGhost (or SMBleedingGhost or CoronaBlue) is a type of security vulnerability, with wormlike features, that affects Windows 10 computers and was first reported publicly on 10 March 2020.

[1][2][3][5][6][7][8][9] A proof of concept (PoC) exploit code was published 1 June 2020 on GitHub by a security researcher.

[8][10] The code could possibly spread to millions of unpatched computers, resulting in as much as tens of billions of dollars in losses.

"[3] Workarounds, according to Microsoft, such as disabling SMB compression and blocking port 445, may help but may not be sufficient.

[3] According to the advisory division of Homeland Security, "Malicious cyber actors are targeting unpatched systems with the new [threat], ... [and] strongly recommends using a firewall to block server message block ports from the internet and to apply patches to critical- and high-severity vulnerabilities as soon as possible.