Impact
An out-of-bounds read in Windows SMB Client allows an attacker to retrieve data from memory that is not normally available, resulting in exposure of private information. The flaw is a buffer over-read (CWE‑125) that occurs when the client processes specially crafted SMB packets, exposing portions of the system memory to unauthorized recipients. The vulnerability does not directly lead to code execution or privilege escalation, but the disclosed data could be leveraged for further attacks or enable reconnaissance of the target system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025, including their Server Core editions. These operating systems run SMB Client components that are impacted by the out‑of‑bounds read.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk to confidentiality. The EPSS score of less than 1% suggests that the likelihood of exploitation at this time is low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote, requiring an attacker to communicate over the network to a victim running a vulnerable SMB Client by sending malicious SMB packets; local privilege does not appear necessary. Compliance with the Microsoft advisory and disabling or restricting SMB traffic reduces both exposure and risk.
OpenCVE Enrichment