CVE-2026-54997
Analyzed Analyzed - Analysis Complete

Use of Uninitialized Resource in Windows SMB Allows Local Information Disclosure

Vulnerability report for CVE-2026-54997, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-20

Assigner: Microsoft Corporation

Description

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-20
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54997 is a vulnerability in Windows SMB (Server Message Block) that involves the use of an uninitialized resource. This flaw allows an authorized attacker with local access to disclose sensitive information from the system.

The vulnerability occurs because the SMB component does not properly initialize a resource before use, which can lead to the exposure of memory contents or other sensitive data to the attacker.

  • Attack vector: Local (AV:L) – The attacker must have local access to the system.
  • Attack complexity: Low (AC:L) – Exploiting the vulnerability does not require special conditions.
  • Privileges required: Low (PR:L) – The attacker needs some level of authorization but not high privileges.
  • Impact: Information disclosure (C:H) – The vulnerability can lead to the exposure of sensitive information.
Impact Analysis

This vulnerability can impact you in several ways if you are using a Windows system with the affected SMB component.

  • Information disclosure: An attacker with local access could exploit this flaw to access sensitive data stored in memory or on the system, such as credentials, personal information, or other confidential data.
  • Privilege escalation risk: While the vulnerability itself does not grant elevated privileges, the disclosed information could be used to facilitate further attacks, such as privilege escalation or lateral movement within a network.
  • Compliance violations: If sensitive data is exposed, it could lead to violations of data protection regulations, depending on the nature of the information disclosed.

The impact is limited to systems where an attacker already has some level of authorized access, so the risk is higher in environments with multiple users or shared systems.

Compliance Impact

This vulnerability can affect compliance with several common standards and regulations, depending on the type of data exposed and the context of the affected system.

  • GDPR (General Data Protection Regulation): If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR requirements. Organizations must ensure the confidentiality and integrity of personal data, and failure to do so could result in fines or legal action.
  • HIPAA (Health Insurance Portability and Accountability Act): If the affected system handles protected health information (PHI), the disclosure of such data due to this vulnerability could constitute a HIPAA violation. Covered entities must implement safeguards to protect PHI, and a breach could lead to penalties.
  • Other regulations: Depending on the industry, other standards like PCI DSS (for payment card data) or sector-specific regulations may also be impacted if the disclosed information falls under their scope.

Organizations should assess the potential exposure of regulated data due to this vulnerability and take appropriate measures to mitigate risks, such as applying patches or implementing compensating controls.

Mitigation Strategies

Microsoft has likely provided patches or updates to address this vulnerability. Apply the latest security updates for Windows SMB as soon as possible.

To mitigate the risk, follow these steps:

  • Check the Microsoft Security Update Guide for CVE-2026-54997 to confirm if your system is affected.
  • Install the latest Windows updates via Windows Update or by downloading the patch from the Microsoft Update Catalog.
  • Ensure that only authorized users have local access to systems running Windows SMB, as the vulnerability requires local access.
  • Monitor Microsoft's official communications for any additional mitigation guidance or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54997. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart