Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-57089Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
Use-after-free vulnerability in Windows SMB Server Network Transport Driver (srvnet.sys) allows an attacker to execute code remotely over the network without authentication.
What this means
What could happen
An attacker could run arbitrary commands on Windows servers running SMB, potentially taking control of HMI systems, data historians, or engineering workstations that manage your critical infrastructure.
Who's at risk
Windows server and desktop operators should care, especially those running Windows Server 2016, 2019, 2022, or 2025 that host SCADA historian databases, HMI servers, or engineering workstations. Any Windows system that shares files over SMB or is part of an Active Directory domain is at risk if exposed to untrusted networks.
How it could be exploited
An attacker sends a specially crafted SMB packet to a Windows system with SMB enabled. The use-after-free flaw in srvnet.sys allows the attacker's packet to trigger code execution without needing valid credentials or user interaction.
Prerequisites
- SMB service must be enabled and listening on the network (typically port 445)
- System must be connected to a network reachable by the attacker
- No valid credentials required
remotely exploitableno authentication requiredlow complexityaffects control system support infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict SMB traffic (port 445) from untrusted networks using a firewall rule or network ACL, allowing only known engineering workstations and trusted file-sharing devices
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Windows security update to all affected systems
Long-term hardening
0/2HARDENINGDisable SMB on systems that do not require file sharing, or restrict SMB to IPv6-only if IPv4 is not needed
HARDENINGSegment Windows servers hosting SCADA, HMI, or historian databases onto a separate network zone that is not directly reachable from untrusted networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e572e633-3168-410a-abb4-626b98be2492Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.