Microsoft Windows SMB Client Improper Authentication Vulnerability Allowing Network Tampering

Vulnerability

A vulnerability has been identified in the Windows SMB Client that involves improper authentication. This flaw allows an unauthorized attacker to intercept and manipulate network communications. The issue arises when the SMB Client connects to an SMB2 Server that does not support SMB Multi-protocol negotiate, creating an opportunity for data tampering.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of data during transmission over the network.

Remediation

Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked within the security update guide.

Added: Oct 14, 2025, 6:03 PM
Updated: Oct 14, 2025, 8:30 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.