Junglewise Threat Intelligence

CVE-2026-69372: Microsoft Windows Network File System out-of-bounds read

CVE-2026-69372 · Severity: medium · CVSS 5.7 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Network File System contains an out-of-bounds read vulnerability that allows an authorized attacker to crash the system and cause a denial of service. An attacker with network access and valid credentials can exploit this to disrupt business operations and impact system availability.

Technical details

The vulnerability is an out-of-bounds read in Windows Network File System (likely NFS or SMB-related component) that can be triggered by an authorized attacker over the network. The root cause involves improper bounds checking when processing network file system requests. An attacker with valid network credentials can send a specially crafted request to trigger the out-of-bounds read, causing the affected service to crash and denying service to legitimate users. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows Network File System <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References