Windows SMB Client Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-65794Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A buffer over-read vulnerability in the Windows SMB Client allows an attacker to disclose information when a user connects to a malicious SMB server. The vulnerability exists in Windows 10 (all versions 1607–22H2), Windows 11 (all versions 23H2–26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker could trigger a buffer over-read in the SMB client to read sensitive data from system memory. While the direct risk to OT operations is limited, this could expose credentials or configuration details used by HMI systems and engineering workstations.
Who's at risk
This affects all engineering workstations and HMI client machines running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all supported versions and architectures. Organizations managing water/wastewater systems, electric distribution, and other utilities that use Windows-based SCADA client software should prioritize systems that access shared data or connect to engineering networks.
How it could be exploited
An attacker would need to configure a malicious SMB server and trick a user into connecting to it (for example, via a network share link in an email or document). When the Windows SMB client connects, the malicious server responds with specially crafted packets that trigger the over-read, leaking data from the client's memory back to the attacker.
Prerequisites
  • User interaction required (user must connect to attacker-controlled SMB share)
  • Network access to the victim's Windows system on SMB ports (445/TCP or 139/TCP)
  • Attacker-controlled SMB server on the network
Remotely exploitableLow complexityUser interaction requiredLow exploit probability (0.7% EPSS)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict SMB access from engineering workstations and HMI clients to only trusted internal file servers and domain controllers using firewall rules
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply August 2026 Microsoft security update to Windows systems (all affected versions listed)
HARDENINGDisable SMB v1 on all Windows systems if still enabled; require SMB v3.1.1 or later
Long-term hardening
0/1
HARDENINGSegment OT networks so that engineering workstations cannot reach untrusted external networks or untrusted Windows systems
API: /api/v1/advisories/438cc727-9429-4f63-9544-ffdd48864084

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Client Information Disclosure Vulnerability | CVSS 6.5 - OTPulse