Description
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference in the Windows SMB Server component can be triggered by an authorized attacker, causing the server process to crash and denying further SMB service over a network. The flaw permits a local or remote user with valid credentials to intentionally disrupt the availability of the SMB service without compromising confidentiality or integrity. The weakness is classified under CWE-476, which describes attempts to dereference null pointers in code that assume non‑null values,

Affected Systems

The flaw affects Microsoft Windows 10 (versions 21H2 and 22H2), Microsoft Windows 11 (versions 24H2, 25H2, and 26H1), and Microsoft Windows Server 2022 and Windows Server 2025 (including Server Core installations). Users running these operating systems on systems where the SMB Server service is enabled are susceptible to the denial of service.

Risk and Exploitability

Based on the description, it is inferred that the attack requires the attacker to have valid credentials to connect to the SMB service over a network. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based with credential dependence. The risk remains moderate because reliance on SMB for file sharing and backups creates potential impact, but overall exploitation remains unlikely due to the low EPSS score.

Generated by OpenCVE AI on July 31, 2026 at 06:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft patch for CVE‑2026‑56168
  • Reduce the attack surface by limiting SMB traffic to trusted subnets or firewalls that only allow authenticated clients
  • If SMB functionality is not essential, disable the SMB Server service or restrict it to minimal required roles to eliminate the vulnerability

Generated by OpenCVE AI on July 31, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Title Windows SMB Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-476
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:52.927Z

Reserved: 2026-06-19T13:53:31.989Z

Link: CVE-2026-56168

cve-icon Vulnrichment

Updated: 2026-07-14T18:00:42.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses