Impact
Allocation of resources without limits or throttling in the Windows SMB Server can cause a denial of service when an attacker with authorized local or network access exploits the flaw. The weakness maps to CWE‑770, meaning that the software fails to protect the system when allocating resources. Once triggered, the SMB service can become unresponsive, leading to service interruption for users who rely on file sharing or printer services. The likely attack vector is over the network via the SMB protocol, where an authorized but potentially malicious client can send requests that force the server to allocate excessive resources. While the description does not explicitly state remote execution, the network‑based nature of SMB and the requirement of an authorized attacker imply that the vulnerability could be triggered from a compromised workstation or a device in the same domain. Because the vulnerability is a moderate‑severity denial‑of‑service flaw (CVSS 6.5), exploitation does not require privileged system access beyond standard SMB capabilities, but it can still disrupt business operations for the affected organization.
Affected Systems
Microsoft Windows 10 version 21H2, Microsoft Windows 10 version 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, Microsoft Windows Server 2022, Microsoft Windows Server 2025 (including Server Core installations). The flaw affects 32‑bit and 64‑bit builds as well as ARM64 and x64 architectures according to the listed CPE entries.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of 1% suggests a low but measurable likelihood that attackers may exploit this flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nonetheless, because an attacker who possesses legitimate SMB credentials can exploit the flaw, vendors and security teams should consider this a significant threat to availability. Environment hardening and prompt patching are recommended to mitigate potential service disruption.
OpenCVE Enrichment