CVE-2026-78446

Windows Distributed File System (DFS) Denial of Service Vulnerability

Beschreibung

Verwendung nach Freigabe im Windows Distributed File System (DFS) ermöglicht es einem berechtigten Angreifer, den Dienst über ein Netzwerk zu verweigern.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.3
Quelle: nvd-v3
47.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 07:00 UTC
CWE-416

Weakness-Klassen (CWE)

  • CWE-416Variant

    Use After Free

    The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 21:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-78446","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-09-08 18:20 UTC· secure@microsoft.com
    • Description: Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
    • CVSS V3.1: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
    • CWE: CWE-416
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/78xxx/CVE-2026-78446.json">CVE-2026-78446</a>
IDCVE-2026-78446