Impact
An overflow occurs in the Windows SMB Client’s heap when processing certain inputs, allowing an attacker with local access to gain higher privileges. The flaw is a classic buffer overflow (CWE-122) that can subvert the intended privilege level of the user, enabling the attacker to execute arbitrary code with elevated rights on the affected machine.
Affected Systems
Microsoft Windows 11, version 26H1 (x64) is vulnerable. Users running this operating system should verify they have the latest update from Microsoft.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but its exploitation requires an attacker to already be authenticated or authorized on the local machine, reducing the likelihood of remote attacks. Because EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, the current risk level is moderate to high for systems that expose themselves to local users who may be malicious. The attack vector is inferred to be local, meaning that attackers need physical or remote access that already provides user privileges to trigger the issue.
OpenCVE Enrichment