ZeroHour

CVE-2026-72949

mass

Null Pointer Dereference DoS in Microsoft Windows SMB Server (srvnet.sys)

CVSS 3.1
7.5 high
EPSS
1%p65
Published
()
Modified
AI analysis

CVE-2026-72949 is a null pointer dereference (CWE-476) in srvnet.sys, the network transport driver used by the Windows SMB Server service. An unauthenticated remote attacker can trigger the flaw by sending crafted traffic to a system that accepts inbound SMB connections, causing the driver to dereference a null pointer. The impact is denial of service only: the affected host likely crashes (kernel bugcheck/blue screen) or hangs until rebooted, with no indication of code execution or data compromise. Any Windows system running the SMB Server service - file servers, domain controllers, print servers, and workstations with sharing enabled - is potentially affected; exact affected version ranges are not present in the available data and should be taken from the Microsoft advisory. No public proof-of-concept, no KEV listing, and an EPSS of 1.1% over 30 days (65th percentile) indicate that exploitation has not been observed and near-term risk is modest.

What to do: Apply the Microsoft security update addressing CVE-2026-72949 to all systems with the Server service enabled, prioritizing internet-facing SMB servers, domain controllers, and file/print servers. Until patched, restrict inbound TCP/445 to trusted networks at the perimeter and via VPN, and monitor for unexplained crashes or reboots. Confirm the affected version list against the official Microsoft advisory, which supersedes this summary.

Affected
Microsoft Windows SMB Server Network Transport Driver (srvnet.sys)
Estimated exposure
massMillions of Windows hosts worldwide (default SMB Server component; on the order of 1M+ hosts expose TCP/445 in public internet scans) — srvnet.sys and the SMB Server service ship and run by default across supported Windows releases, and public internet scans of TCP/445 routinely find roughly a million or more exposed endpoints, with many more SMB servers sitting behind…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.