Impact
A heap‑based buffer overflow exists in the SMBv3 Server component of Windows. The flaw allows an authenticated attacker who can communicate over the SMB protocol to trigger an overflow and execute arbitrary code on the target system. The vulnerability is identified as CWE–122, which reflects a classic heap overrun condition. The principal consequence is that a compromised machine could become fully controlled by an attacker, enabling the execution of additional malware or data exfiltration. Based on the description, it is inferred that the attacker must be able to send malicious packets over SMB to the target to trigger the exploit.
Affected Systems
The affected products span a broad range of Microsoft Windows operating systems and server editions. The list includes Windows 10 from build 1607 through 22H2, Windows 11 from version 23H2 through 26H1, Windows 10 21H2, and the Windows Server family from 2012 to 2025, including both full and Server Core installations. All of these releases rely on the SMBv3 protocol, which is the entry point for the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, and while an EPSS score is not available, the lack of a KEV listing does not diminish the risk posed by a high‑confidence remote exploit. The flaw requires an attacker to first gain legitimate SMB authentication to the target, implying that SMB traffic is the attack vector used to deliver the crafted packets. Once authenticated, the attacker can send specially crafted SMB packets that trigger the heap overflow, leading to remote code execution on the host. The exploitation window is persistent until the relevant Windows updates are applied, making the vulnerability a significant threat to any networked environment that relies on SMBv3 traffic.
OpenCVE Enrichment