Description
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: 1.1% Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Allocation of resources without limits or throttling in the Windows SMB Server can cause a denial of service when an attacker with authorized local or network access exploits the flaw. The weakness maps to CWE‑770, meaning that the software fails to protect the system when allocating resources. Once triggered, the SMB service can become unresponsive, leading to service interruption for users who rely on file sharing or printer services. The likely attack vector is over the network via the SMB protocol, where an authorized but potentially malicious client can send requests that force the server to allocate excessive resources. While the description does not explicitly state remote execution, the network‑based nature of SMB and the requirement of an authorized attacker imply that the vulnerability could be triggered from a compromised workstation or a device in the same domain. Because the vulnerability is a moderate‑severity denial‑of‑service flaw (CVSS 6.5), exploitation does not require privileged system access beyond standard SMB capabilities, but it can still disrupt business operations for the affected organization.

Affected Systems

Microsoft Windows 10 version 21H2, Microsoft Windows 10 version 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, Microsoft Windows Server 2022, Microsoft Windows Server 2025 (including Server Core installations). The flaw affects 32‑bit and 64‑bit builds as well as ARM64 and x64 architectures according to the listed CPE entries.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of 1% suggests a low but measurable likelihood that attackers may exploit this flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nonetheless, because an attacker who possesses legitimate SMB credentials can exploit the flaw, vendors and security teams should consider this a significant threat to availability. Environment hardening and prompt patching are recommended to mitigate potential service disruption.

Generated by OpenCVE AI on September 9, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security update that addresses CVE‑2026‑69374, as detailed in Microsoft’s update guide.
  • Configure SMB settings to limit the number of simultaneous connections and throttle resource allocation where possible.
  • Restrict SMB traffic to trusted internal networks and enforce strict firewall rules to prevent unauthorized access.

Generated by OpenCVE AI on September 9, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
Title Windows SMB Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-770
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 21h2 Windows 10 22h2 Windows 10 22h2 Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:17.828Z

Reserved: 2026-08-03T20:54:04.486Z

Link: CVE-2026-69374

cve-icon Vulnrichment

Updated: 2026-09-08T20:49:04.803Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:57.903

Modified: 2026-09-17T15:43:46.097

Link: CVE-2026-69374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:08:46Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling