Junglewise Threat Intelligence

CVE-2026-54997: Microsoft Windows SMB information disclosure via uninitialized resource

CVE-2026-54997 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows file-sharing component (SMB) that could allow a user already logged into a system to view sensitive information they are not authorized to see. This occurs because the system fails to properly clear memory before reusing it, potentially exposing data from other processes or users. While this does not allow an attacker to take over the computer or delete files, it poses a risk to data confidentiality on shared systems.

Technical details

A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in the Microsoft Windows SMB implementation. An attacker with local access and low-level privileges can exploit this flaw to disclose sensitive information from the system's memory. The root cause is the failure of the SMB component to properly initialize a resource or buffer before it is returned to a user-mode process. This is a local information disclosure vulnerability; it does not provide a path for remote code execution or privilege escalation directly, but the leaked data could be used to facilitate further attacks. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via MSRC.

References

Related threats