Junglewise Threat Intelligence

CVE-2026-72949: Microsoft Windows SMB Server null pointer dereference in srvnet.sys

CVE-2026-72949 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

The Windows SMB Server Network Transport Driver (srvnet.sys) contains a null pointer dereference vulnerability that allows an unauthenticated attacker to remotely crash the SMB service, disrupting file sharing and network access for affected systems. This can lead to denial of service, preventing legitimate users from accessing shared files and resources across the network.

Technical details

A null pointer dereference vulnerability exists in the Windows SMB Server Network Transport Driver (srvnet.sys), allowing an unauthenticated attacker to send a specially crafted network packet over SMB to trigger a null pointer exception. The vulnerability requires no authentication or user interaction, and the attack vector is network-based, making it readily exploitable by remote attackers. Successful exploitation causes the SMB service to crash, resulting in a denial of service condition. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats