Impact
A buffer over-read in the Windows SMB client allows an attacker to read uninitialized memory and disclose sensitive data across the network. This flaw, identified as CWE-126, can lead to remote information disclosure when an attacker can reach a vulnerable SMB client.
Affected Systems
The vulnerability applies to Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, and 26H1; and Windows Server editions from 2012 through 2025, including Server Core variants. Any host running these operating systems and utilizing the SMB client is potentially affected.
Risk and Exploitability
With a CVSS score of 6.5, the flaw carries moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and it is not listed in CISA's KEV catalog. Attackers can exploit the issue remotely over SMB when network traffic can reach the SMB client, but the overall threat level remains moderate due to the required network access and the low exploitation likelihood.
OpenCVE Enrichment