Impact
The vulnerability is a null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys). An unauthenticated attacker can trigger a crash in the SMB service, causing the computer to become unreachable on the network. This results in a denial of service without providing the attacker any additional privileges, aligning with CWE-476.
Affected Systems
Affected systems include Microsoft Windows 11 releases – versions 23H2, 24H2, 25H2, and 26H1 – as well as Microsoft Windows Server 2022 and Microsoft Windows Server 2025 (including Server Core installations). The issue spans both x64 and arm64 architectures for the Windows 11 variants and all architectures for the server editions.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity, and it is not listed in the CISA KEV catalog. The EPSS score of 1% suggests a low but non‑zero probability that the vulnerability will be actively exploited. The danger lies in the vulnerability’s ability to be exploited over SMB traffic from an unauthenticated source, which can lead to a service disruption. The likely attack vector is network‑based, requiring the attacker to send a specially crafted packet to the infected SMB server to trigger the null‑dereference and crash the service.
OpenCVE Enrichment