Executive brief
Windows Network File System contains an out-of-bounds read vulnerability that allows an authorized attacker to crash the system and cause a denial of service. An attacker with network access and valid credentials can exploit this to disrupt business operations and impact system availability.
Technical details
The vulnerability is an out-of-bounds read in Windows Network File System (likely NFS or SMB-related component) that can be triggered by an authorized attacker over the network. The root cause involves improper bounds checking when processing network file system requests. An attacker with valid network credentials can send a specially crafted request to trigger the out-of-bounds read, causing the affected service to crash and denying service to legitimate users. Microsoft has released patches to address this issue.
Affected products
- Microsoft Windows Network File System <UNKNOWN>
Timeline
- 2026-09-08: disclosed