Vulnerability record · CVE-2006-1315 · published 11 July 2006
CVE-2006-1315: Windows Server Service SMB buffer info disclosure
Microsoft · Server Service
The SRV.SYS Server Service driver in Windows 2000, XP and Server 2003 fails to properly initialize SMB buffers, allowing crafted requests to leak memory contents. This exposes potentially sensitive data from kernel memory to any remote client that can reach SMB.
Description
The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityCVSS 2.0 rates this 5.0 (medium) with confidentiality-only impact, but the high EPSS percentile and unauthenticated network reachability warrant prompt patching.
What it is
The SRV.SYS Server Service driver in Windows 2000, XP and Server 2003 fails to properly initialize SMB buffers, allowing crafted requests to leak memory contents. This exposes potentially sensitive data from kernel memory to any remote client that can reach SMB.
Impact
An unauthenticated remote attacker can read uninitialized memory returned in SMB responses, potentially disclosing sensitive information such as fragments of prior buffer contents. No code execution or data modification is possible from this flaw alone.
Attack surface
Reachable over the network via SMB (port 445/139) with no authentication or user interaction required, per the AV:N/AC:L/Au:N vector. Any host exposing the Windows Server Service is a candidate.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, though EPSS is high (0.4875, 98.8th percentile), suggesting elevated predicted exploitation activity. No ransomware association is documented.
What to do
- Apply Microsoft security bulletin MS06-035 (the vendor fix for this issue) to all affected Windows 2000, XP and Server 2003 systems.
- Block inbound SMB (TCP 445 and 139) at network boundaries and restrict it to trusted internal segments.
- Disable the Server service on hosts that do not need to share files or printers.
- Retire or isolate unsupported Windows 2000/XP/Server 2003 systems that cannot be patched.
- Monitor for anomalous SMB traffic from untrusted sources as a compensating control.
Detection
- Inspect SMB traffic for malformed or unusual requests targeting the Server Service, especially from unexpected external hosts.
- Alert on SMB connections to port 445/139 originating outside trusted network ranges.
- Review host logs for Server Service errors or crashes that could accompany crafted SMB requests.
- Track unpatched Windows 2000/XP/Server 2003 hosts still exposing SMB on the network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1315 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2006-1315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.