Windows SMB Server Denial of Service Vulnerability

MonitorCVSS 6.5CVE-2026-69374Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A denial of service vulnerability in Windows SMB Server allows an authorized attacker to exhaust server resources by sending specially crafted SMB requests without limits or throttling. This can make the SMB service unresponsive, disconnecting users and halting file and print sharing. The vulnerability affects all versions of Windows Server 2022, 2025, Windows 10, and Windows 11.

What this means
What could happen
An attacker with network access and valid credentials could send specially crafted SMB requests that exhaust server resources, causing the Windows SMB service to become unresponsive and disconnecting legitimate users or halting file sharing and device communication.
Who's at risk
This affects all Windows Server 2022, 2025, and Windows 10/11 systems used as file servers, domain controllers, or any OT workstations running modern Windows OS. Water and electric utilities using Windows-based SCADA servers, HMI workstations, or engineering systems are at risk if those systems run SMB file sharing services.
How it could be exploited
An attacker with valid user credentials on your network sends malformed SMB packets to a Windows Server or client machine running SMB. The server does not limit how many resources it allocates to handle these requests, allowing the attacker to exhaust memory or CPU and make the service unavailable. The attack requires network access to port 445 (SMB) and valid credentials to initiate the connection.
Prerequisites
  • Network access to port 445 (SMB)
  • Valid user credentials to authenticate to the SMB service
  • Access from internal network or external if SMB is exposed
remotely exploitablerequires valid credentialsaffects Windows file sharing and device communicationlow patch priority (exploitation unlikely, but resource exhaustion can disrupt operations)
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (18)
18 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7725
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict SMB access (port 445) at the firewall to only authorized internal networks and block from untrusted external sources
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all affected Windows Server and Windows 10/11 systems
HARDENINGDisable SMB v1 if not required for legacy system compatibility
Long-term hardening
0/1
HARDENINGSegment OT and IT networks so that SMB services on control systems are not directly accessible from general IT networks
API: /api/v1/advisories/53e8ba9e-a11c-4f41-ae82-4864e03d0e61

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Server Denial of Service Vulnerability | CVSS 6.5 - OTPulse