Windows SMB Server Denial of Service Vulnerability

MonitorCVSS 6.5CVE-2026-56168Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A null pointer dereference in Windows SMB Server allows an authenticated attacker on the network to cause denial of service by sending a crafted SMB message, crashing the SMB service and disrupting file sharing and network authentication.

What this means
What could happen
An authenticated attacker on your network could crash the Windows SMB server by sending a specially crafted message, temporarily disrupting file sharing, authentication services, and any OT network operations that depend on Windows file or print services.
Who's at risk
Windows Server administrators and utilities running Windows-based OT networks, SCADA data aggregators, or engineering workstations that rely on SMB for file or authentication services. This includes any site using Windows as an Active Directory domain controller or file server for process data or control system configurations.
How it could be exploited
An attacker with valid network credentials sends a malformed SMB message to the Windows SMB server (typically port 445). The server fails to validate a pointer before dereferencing it, causing a crash and denial of service. No interaction or elevation of privileges is needed beyond network access and basic authentication.
Prerequisites
  • Valid credentials on your network or AD domain
  • Network access to port 445 (SMB) on affected Windows systems
  • System must be running an affected, unpatched Windows version
remotely exploitablerequires valid credentialsdenial of service impactlow complexity attackaffects Windows infrastructure critical to OT operations
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/6
Do now
0/1
WORKAROUNDRestrict SMB access (port 445) at the firewall to only authorized internal subnets and block inbound SMB from untrusted networks
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply the July 2026 security update to Windows Server 2022 (Build 10.0.20348.5386 or later)
Windows Server 2025
HOTFIXApply the July 2026 security update to Windows Server 2025 (Build 10.0.26100.33158 or later)
All products
HOTFIXApply the July 2026 security update to Windows 10 Version 21H2 (Build 10.0.19044.7548 or later)
HOTFIXApply the July 2026 security update to Windows 10 Version 22H2 (Build 10.0.19045.7548 or later)
HOTFIXApply the July 2026 security update to Windows 11 all versions (Build 10.0.26100.8875 or later for 24H2; Build 10.0.26200.8875 or later for 25H2; Build 10.0.28000.2269+ for 26H1 x64)
API: /api/v1/advisories/5639b93c-5bed-4549-90b4-c6abb63dde00

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Server Denial of Service Vulnerability | CVSS 6.5 - OTPulse