Windows SMB Client Elevation of Privilege Vulnerability by Microsoft
CVE-2026-40410
7HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40410?
A use-after-free vulnerability in the Windows SMB Client can be exploited by an authorized attacker to gain elevated privileges on the affected system. This issue allows the attacker to execute arbitrary code with elevated permissions, potentially leading to unauthorized access or system compromise. Microsoft has released a security advisory addressing this vulnerability, and users are encouraged to apply the recommended patches immediately to safeguard their systems.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291