Windows SMB Client Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-69544Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in the Windows SMB Client component allows an authorized user with local access to escalate privileges on Windows 11 version 26H1 systems (x64 and ARM64). The vulnerability requires user-level credentials and local or interactive access to exploit. Exploitation is assessed as less likely.

What this means
What could happen
An authorized user on a Windows 11 system could exploit a heap-based buffer overflow in the SMB client to gain higher-level privileges on that machine, potentially allowing them to access sensitive files, modify system settings, or interfere with processes running on that workstation.
Who's at risk
This affects Windows 11 workstations and desktops (both x64 and ARM64 systems) running version 26H1 that are used in utility IT environments. This is primarily an IT concern rather than OT control systems, but any Windows 11 systems supporting OT engineering workstations, HMI servers, or historian systems should be patched to prevent lateral movement into industrial networks.
How it could be exploited
An attacker with user-level access to a Windows 11 system could trigger a heap-based buffer overflow in the SMB client component, bypassing normal privilege restrictions and escalating to system-level access. This requires local access and valid user credentials on the target machine.
Prerequisites
  • Valid user account credentials on the Windows 11 system
  • Local or interactive access to the Windows 11 machine
  • SMB client service enabled (default configuration)
Low complexity exploitRequires local access and user credentialsAffects workstation/desktop systems primarilyLow EPSS score (0.3%)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's 2026-Sep security update to Windows 11 systems running version 26H1
HARDENINGPrioritize patching workstations that are used by multiple users or in shared environments where privilege escalation risk is higher
API: /api/v1/advisories/bf149915-11ee-4944-bff5-49d66ceb734d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.