Executive brief
Windows SMB Client is a core networking component used by Windows systems to connect to shared files and printers on corporate networks. A heap-based buffer overflow in this component allows an authenticated attacker with local access to execute code with elevated system privileges, potentially leading to full system compromise and lateral movement across the network.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows SMB Client component, allowing an authorized local attacker to elevate privileges. The vulnerability requires the attacker to have local access to the system. Successful exploitation permits the attacker to execute arbitrary code with elevated system privileges. No active exploitation in the wild has been reported at this time. A patch is expected to be available through Microsoft's standard security update channels.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed