Windows SMB
by Microsoft
CVEs (16)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-33073 | Hig | 0.77 | 8.8 | 0.80 | KEV | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| CVE-2022-24500 | Hig | 0.60 | 8.8 | 0.37 | Apr 15, 2022 | Windows SMB Remote Code Execution Vulnerability | ||
| CVE-2024-43642 | Hig | 0.54 | 7.5 | 0.62 | Nov 12, 2024 | Windows SMB Denial of Service Vulnerability | ||
| CVE-2020-17140 | Hig | 0.54 | 8.1 | 0.12 | Dec 10, 2020 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2025-32718 | Hig | 0.51 | 7.8 | 0.00 | Jun 10, 2025 | Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-26245 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows SMB Elevation of Privilege Vulnerability | ||
| CVE-2025-50169 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | ||
| CVE-2021-28324 | Hig | 0.49 | 7.5 | 0.06 | Apr 13, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2018-8335 | Hig | 0.49 | 7.5 | 0.09 | Sep 13, 2018 | A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012,… | ||
| CVE-2021-28325 | Med | 0.47 | 6.5 | 0.62 | Apr 13, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2025-48802 | Med | 0.42 | 6.5 | 0.01 | Jul 8, 2025 | Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2021-33783 | Med | 0.42 | 6.5 | 0.03 | Jul 14, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2025-29956 | Med | 0.35 | 5.4 | 0.01 | May 13, 2025 | Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-58531 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-54997 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | ||
| CVE-2026-49801 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
- risk 0.77cvss 8.8epss 0.80
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 8.8epss 0.37
Windows SMB Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.62
Windows SMB Denial of Service Vulnerability
- risk 0.54cvss 8.1epss 0.12
Windows SMB Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Windows SMB Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.06
Windows SMB Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.09
A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012,…
- risk 0.47cvss 6.5epss 0.62
Windows SMB Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.03
Windows SMB Information Disclosure Vulnerability
- risk 0.35cvss 5.4epss 0.01
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 5.5epss 0.00
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.