Security readout for executives and security teams
Plain-English summary
CVE-2020-17047 is a Microsoft Windows Network File System denial-of-service vulnerability. A remote, unauthenticated attacker could affect availability, but the provided sources do not show confidentiality or integrity impact. Business risk is service disruption on affected Windows systems rather than data theft.
Executive priority
Treat as high priority for availability-sensitive Windows file services. It is not sourced as data compromise or active exploitation, but unauthenticated network-triggered denial of service can disrupt operations if exposed systems remain unpatched.
Technical view
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, scored 7.5. It affects multiple listed Windows client and server versions, including Windows Server 2016, 2019, 1903, 1909, 2004, 20H2 and Windows 7, 8.1, and Windows 10 releases.
Likely exposure
Exposure is most likely where affected Windows systems run or expose Microsoft Network File System functionality. The source bundle lists broad Windows client and server coverage, but does not identify specific configurations, ports, or deployment prerequisites.
Exploitation context
CISA KEV status is false in the provided bundle, and no cited source states active exploitation. The CVSS temporal vector indicates proof-of-concept exploit maturity, but the bundle does not provide exploit details or confirm real-world use.
Researcher notes
Evidence is limited to the CVE description, affected product list, CVSS vector, KEV=false flag, and MSRC reference. No CWE, root cause, packet-level trigger, or specific KB mapping is included in the provided bundle.
Mitigation direction
- Review Microsoft MSRC guidance for CVE-2020-17047.
- Apply relevant Microsoft security updates for affected Windows versions.
- Prioritize internet-reachable or business-critical NFS hosts.
- Restrict NFS exposure to trusted networks where operationally possible.
- Retire or isolate unsupported affected Windows versions.
Validation and detection
- Inventory Windows systems matching the affected product list.
- Confirm whether Microsoft NFS functionality is enabled or reachable.
- Verify installed Microsoft security updates against MSRC guidance.
- Check monitoring for unexplained NFS service crashes or availability loss.
- Document exceptions for systems that cannot be patched promptly.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-17047 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17047CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
