Executive brief
Windows SMB Client is the component that allows a computer to connect to and access shared files and printers on network servers. An out-of-bounds read vulnerability allows an authorized user on the same system to read sensitive information from the computer's memory, potentially exposing passwords, keys, or other confidential data.
Technical details
This vulnerability is an out-of-bounds read flaw in the Windows SMB Client, a core networking component. The vulnerability requires local access and existing user privileges to trigger. An authorized attacker can exploit improper memory handling in SMB processing to read memory regions outside intended bounds, disclosing sensitive information from the host system. The vulnerability has a CVSS base score of 5.5 (medium severity). Patches are expected to be available from Microsoft.
Affected products
- Microsoft Windows SMB Client
Timeline
- 2026-09-08: disclosed