Executive brief
Windows SMB Server, a core component that allows file and print sharing across corporate networks, is vulnerable to resource exhaustion attacks by authorized users. An attacker with valid network credentials can trigger uncontrolled resource allocation to disrupt server availability and impact business operations such as file access and printing services.
Technical details
The vulnerability stems from insufficient resource limits and throttling in Windows SMB Server, allowing allocation without constraints. An authenticated attacker on the network can exploit this to exhaust server memory, CPU, or connection resources, causing denial of service. The attack requires valid SMB credentials but does not require elevated privileges. No patch information is currently available in the advisory materials provided.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed