Impact
An out‑of‑bounds read in the Windows SMB client allows an attacker who is already authorized on a network to read data that the application should not expose. This leads to disclosure of potentially sensitive information contained in memory, compromising confidentiality without providing remote code execution or denial of service.
Affected Systems
The vulnerability affects a wide range of Microsoft Windows operating systems. It applies to Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server editions Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 – both full and Server Core installations.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting no documented widespread exploitation. The attack vector is network‑based and requires that the attacker is already authenticated to the SMB service, meaning it is relevant primarily within enterprise or compromised network environments.
OpenCVE Enrichment