Impact
A buffer over‑read in the Windows Network File System (WNFS) can be triggered by an unauthorized attacker. The flaw causes the WNFS service to terminate, effectively denying legitimate users access to the file system over the network. The vulnerability is a classic CWE-126 buffer over‑read.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 5.9 positions the vulnerability as medium severity. EPSS indicates a probability of exploitation of less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is network access to the target, where an attacker can send malicious WNFS requests to trigger the denial. The patch from Microsoft mitigates the issue, and no additional exploit conditions are disclosed in the available data.
OpenCVE Enrichment