Impact
A use‑after‑free vulnerability in the Windows SMB Server Network Transport Driver (srvnet.sys) allows an attacker to send crafted SMB packets to an affected host, leading to memory corruption and execution of arbitrary code on the target system. The vulnerability is a classic use‑after‑free flaw identified as CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high threat. The EPSS score of less than 1 % indicates a very low probability of exploitation observed in the wild. Based on the vulnerability description, it is inferred that an attacker would need network access to the SMB service and that the likely attack vector is remote network-based, using malicious SMB traffic to trigger the memory corruption and achieve remote code execution. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment