7.5
CVE-2026-72949
- EPSS 1.15%
- Veröffentlicht 08.09.2026 17:14:04
- Zuletzt bearbeitet 21.09.2026 19:28:53
- Erkennungen
Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 11 23h2 HwPlatform arm64 Version < 10.0.22631.7582
Microsoft ≫ Windows 11 23h2 HwPlatform x64 Version < 10.0.22631.7582
Microsoft ≫ Windows 11 24h2 HwPlatform arm64 Version < 10.0.26100.9445
Microsoft ≫ Windows 11 24h2 HwPlatform x64 Version < 10.0.26100.9445
Microsoft ≫ Windows 11 25h2 HwPlatform arm64 Version < 10.0.26200.9445
Microsoft ≫ Windows 11 25h2 HwPlatform x64 Version < 10.0.26200.9445
Microsoft ≫ Windows 11 26h1 HwPlatform arm64 Version < 10.0.28000.2954
Microsoft ≫ Windows 11 26h1 HwPlatform x64 Version < 10.0.28000.2954
Microsoft ≫ Windows Server 2022 HwPlatform x64 Version < 10.0.20348.5622
Microsoft ≫ Windows Server 2025 HwPlatform x64 Version < 10.0.26100.33438
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.15% | 0.65 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72949