Sceawere

Vulnerability Detail

CVE-2026-62782UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows SMB Client Out-of-Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-11T17:18:31.600Z",
  "pubdate": "2026-08-11T17:18:31.600Z",
  "executiveSummary": "An out-of-bounds read vulnerability has been identified within the Windows SMB Client component, posing significant information disclosure risks across enterprise networks.\nThis vulnerability allows an unauthenticated, remote attacker to interact with vulnerable systems and extract sensitive memory contents over the network without requiring user interaction or elevated privileges.\nThe flaw stems from improper handling of crafted Server Message Block packets, leading to memory exposure when the client processes anomalous responses from a malicious or compromised server.\nSuccessful exploitation exposes sensitive kernel or application memory, which can subsequently be leveraged by threat actors to facilitate advanced attacks, bypass security controls, or orchestrate secondary exploitation phases.\nGiven the network-accessible vector and the low barrier to entry for unauthorized attackers, organizations face heightened risk of internal data leakage and reconnaissance exposure.\nRemediation requires immediate deployment of official vendor security updates across all affected Windows SMB Client deployments, alongside network segmentation and protocol hardening best practices.",
  "technicalDetails": "The vulnerability resides within the Windows SMB Client subsystem, specifically in the routines responsible for parsing and processing incoming Server Message Block protocol responses.\nThe root cause is classified as an out-of-bounds read, originating from insufficient bounds checking and validation of length fields within network packet headers before memory read operations are executed.\nWhen a client establishes an SMB session with a malicious or spoofed server, the peer can transmit specially crafted SMB response packets containing manipulated size descriptors or offset values.\nUpon receiving these anomalous packets, the vulnerable parsing functions fail to accurately compute buffer boundaries, causing the SMB Client to read memory addresses outside the allocated heap or stack boundaries associated with the network buffer.\nThis unauthorized memory read operation captures adjacent heap or stack contents, which may contain sensitive residual data, including internal system pointers, authentication session identifiers, or previously processed transaction data.\nThe captured memory contents are subsequently encapsulated and reflected back to the attacker within anomalous protocol response fields or error messages, completing the information disclosure attack flow.\nExploitation requires network connectivity to the targeted client or the ability to spoof/redirect SMB traffic, allowing attackers to initiate or intercept SMB communications.\nThe attack vector is completely remote, requires no authentication, and involves zero privileges or user interaction, making it highly effective for automated network reconnaissance and pre-exploitation intelligence gathering.\nPost-exploitation impact is primarily centered on confidentiality breaches, as the leaked memory structures can aid attackers in mapping internal memory layouts and bypassing defense mechanisms such as Address Space Layout Randomization in chained exploit scenarios."
}
CVE-2026-62782: Windows SMB Client Out-of-Bounds Read (MEDIUM Severity, CVSS: 6.5) - Sceawere