Windows SMB Server Elevation of Privilege vulnerabilities
12/01/2026 - Download
Product
Windows
Severity
High
Fixed Version(s)
See Microsoft advisories
Affected Version(s)
See Microsoft advisories
CVE Number
Authors
Description
Presentation
Windows is a product line of proprietary graphical operating systems developed and marketed by Microsoft.
Issue(s)
A lack of check in Windows SMB server allows an authenticated attacker to perform a reflection attack to elevate privileges locally on any Windows machine which does not enforce SMB signing.
Timeline
| Date | Description |
|---|---|
| 2025.10.05 | First advisory sent to MSRC |
| 2025.10.31 | Second advisory sent to MSRC |
| 2025.12.02 | First vulnerability acknowledged by Microsoft |
| 2026.02.19 | Second vulnerability acknowledged by Microsoft |
| 2026.03.10 | Patch published by Microsoft in March 2026 Patch Tuesday |
| 2026.05.01 | Public release of this advisory |
Technical details
Description
The complete analysis of the vulnerabilities can be found in the associated blogposts:
Impact
An authenticated attacker can elevate privileges locally on any Windows machine which does not enforce SMB signing.