Impact
A null pointer dereference in the Windows SMB Server component can be triggered by an authorized attacker, causing the server process to crash and denying further SMB service over a network. The flaw permits a local or remote user with valid credentials to intentionally disrupt the availability of the SMB service without compromising confidentiality or integrity. The weakness is classified under CWE-476, which describes attempts to dereference null pointers in code that assume non‑null values,
Affected Systems
The flaw affects Microsoft Windows 10 (versions 21H2 and 22H2), Microsoft Windows 11 (versions 24H2, 25H2, and 26H1), and Microsoft Windows Server 2022 and Windows Server 2025 (including Server Core installations). Users running these operating systems on systems where the SMB Server service is enabled are susceptible to the denial of service.
Risk and Exploitability
Based on the description, it is inferred that the attack requires the attacker to have valid credentials to connect to the SMB service over a network. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based with credential dependence. The risk remains moderate because reliance on SMB for file sharing and backups creates potential impact, but overall exploitation remains unlikely due to the low EPSS score.
OpenCVE Enrichment