CVE-2026-72949
massNull Pointer Dereference DoS in Microsoft Windows SMB Server (srvnet.sys)
CVE-2026-72949 is a null pointer dereference (CWE-476) in srvnet.sys, the network transport driver used by the Windows SMB Server service. An unauthenticated remote attacker can trigger the flaw by sending crafted traffic to a system that accepts inbound SMB connections, causing the driver to dereference a null pointer. The impact is denial of service only: the affected host likely crashes (kernel bugcheck/blue screen) or hangs until rebooted, with no indication of code execution or data compromise. Any Windows system running the SMB Server service - file servers, domain controllers, print servers, and workstations with sharing enabled - is potentially affected; exact affected version ranges are not present in the available data and should be taken from the Microsoft advisory. No public proof-of-concept, no KEV listing, and an EPSS of 1.1% over 30 days (65th percentile) indicate that exploitation has not been observed and near-term risk is modest.
What to do: Apply the Microsoft security update addressing CVE-2026-72949 to all systems with the Server service enabled, prioritizing internet-facing SMB servers, domain controllers, and file/print servers. Until patched, restrict inbound TCP/445 to trusted networks at the perimeter and via VPN, and monitor for unexplained crashes or reboots. Confirm the affected version list against the official Microsoft advisory, which supersedes this summary.
| Microsoft Windows SMB Server Network Transport Driver (srvnet.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.