Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-57089Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

Use-after-free vulnerability in Windows SMB Server Network Transport Driver (srvnet.sys) allows an attacker to execute code remotely over the network without authentication.

What this means
What could happen
An attacker could run arbitrary commands on Windows servers running SMB, potentially taking control of HMI systems, data historians, or engineering workstations that manage your critical infrastructure.
Who's at risk
Windows server and desktop operators should care, especially those running Windows Server 2016, 2019, 2022, or 2025 that host SCADA historian databases, HMI servers, or engineering workstations. Any Windows system that shares files over SMB or is part of an Active Directory domain is at risk if exposed to untrusted networks.
How it could be exploited
An attacker sends a specially crafted SMB packet to a Windows system with SMB enabled. The use-after-free flaw in srvnet.sys allows the attacker's packet to trigger code execution without needing valid credentials or user interaction.
Prerequisites
  • SMB service must be enabled and listening on the network (typically port 445)
  • System must be connected to a network reachable by the attacker
  • No valid credentials required
remotely exploitableno authentication requiredlow complexityaffects control system support infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict SMB traffic (port 445) from untrusted networks using a firewall rule or network ACL, allowing only known engineering workstations and trusted file-sharing devices
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected systems
Long-term hardening
0/2
HARDENINGDisable SMB on systems that do not require file sharing, or restrict SMB to IPv6-only if IPv4 is not needed
HARDENINGSegment Windows servers hosting SCADA, HMI, or historian databases onto a separate network zone that is not directly reachable from untrusted networks
API: /api/v1/advisories/e572e633-3168-410a-abb4-626b98be2492

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse