Impact
A use‑after‑free flaw in Windows Distributed File System (DFS) allows an attacker with authorized credentials to trigger a denial of service that disrupts DFS functionality over the network. The vulnerability does not lead to remote code execution or data disclosure; its primary effect is the instability or shutdown of the DFS service, affecting availability for users who rely on shared namespaces.
Affected Systems
The flaw affects a broad set of Microsoft Windows products, including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Windows Server from 2012 to 202, including Server Core installations where applicable. Any machine that runs the DFS role or clients connecting to DFS namespaces is subject to the impact.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have valid credentials and network access to a DFS host or client, implying an authorized or privileged user exploits the flaw. Once triggered, the DFS service may crash or become unresponsive, causing a drop in shared file availability for users within the affected domain or network segment.
OpenCVE Enrichment