Description
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an error in the authentication algorithm used by the Windows SMB Server. An attacker who has authorized or sufficient access across a network can exploit the flaw to elevate privileges, potentially gaining system‑level rights on the host and thereby compromising the confidentiality, integrity, or availability of the machine.

Affected Systems

Affected operating systems include Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2022 and 2025, including Server Core installations. All variants enumerated in the provided CPE entries are vulnerable.

Risk and Exploitability

The CVSS score of 8.8 marks the flaw as high severity, while the EPSS score of less than 1% indicates a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a network‑based SMB request originating from an attacker who already has authorized access to the host; the flaw allows privilege escalation once that request reaches the SMB Server.

Generated by OpenCVE AI on July 31, 2026 at 08:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates from Microsoft to remediate the authentication flaw
  • Restrict SMB traffic to trusted zones by configuring firewall rules and disabling SMB on unnecessary interfaces
  • Implement network segmentation and least‑privilege controls so that only essential services can use SMB
  • Where feasible, disable legacy SMB protocols that are no longer required

Generated by OpenCVE AI on July 31, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Title Windows SMB Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-303
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:46.146Z

Reserved: 2026-06-04T18:48:26.815Z

Link: CVE-2026-50360

cve-icon Vulnrichment

Updated: 2026-07-15T13:42:22.667Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:45:17Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm