Executive brief
A vulnerability in the Windows Server Message Block (SMB) service could allow an authorized user to crash the system remotely. SMB is a standard protocol used by Windows for sharing files and printers across a network. While this flaw does not allow for data theft, it can be used to disrupt business operations by causing a denial-of-service state on affected servers and workstations.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in the Microsoft Windows SMB Server component. An attacker with low-privileged network access can exploit this flaw by sending specially crafted requests to the SMB service. Successful exploitation results in a denial-of-service (DoS) condition, typically manifesting as a system crash or service interruption. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD