Impact
The vulnerability is an out‑of‑bounds read in the Windows Network File System layer that allows an authenticated attacker to trigger a denial of service by causing the system to crash or become unresponsive over the network.
Affected Systems
Microsoft Windows 10 (1607 and 1809) and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations are affected.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, so the exact likelihood of exploitation is unknown. Based on the description, it is inferred that an attacker would need to exploit the SMB protocol to trigger the out‑of‑bounds read and cause a service interruption. Because it only leads to service denial and not data compromise, the overall risk is moderate but the outage can have significant impact on business availability.
OpenCVE Enrichment