← Vulnerability feed

Vulnerability record · CVE-2006-1315 · published 11 July 2006

CVE-2006-1315: Windows Server Service SMB buffer info disclosure

Microsoft · Server Service

The SRV.SYS Server Service driver in Windows 2000, XP and Server 2003 fails to properly initialize SMB buffers, allowing crafted requests to leak memory contents. This exposes potentially sensitive data from kernel memory to any remote client that can reach SMB.

5.0 CVSS 2.0 Medium EPSS 49% · top 1.2%
5.0CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityCVSS 2.0 rates this 5.0 (medium) with confidentiality-only impact, but the high EPSS percentile and unauthenticated network reachability warrant prompt patching.

What it is

The SRV.SYS Server Service driver in Windows 2000, XP and Server 2003 fails to properly initialize SMB buffers, allowing crafted requests to leak memory contents. This exposes potentially sensitive data from kernel memory to any remote client that can reach SMB.

Impact

An unauthenticated remote attacker can read uninitialized memory returned in SMB responses, potentially disclosing sensitive information such as fragments of prior buffer contents. No code execution or data modification is possible from this flaw alone.

Attack surface

Reachable over the network via SMB (port 445/139) with no authentication or user interaction required, per the AV:N/AC:L/Au:N vector. Any host exposing the Windows Server Service is a candidate.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, though EPSS is high (0.4875, 98.8th percentile), suggesting elevated predicted exploitation activity. No ransomware association is documented.

What to do

  • Apply Microsoft security bulletin MS06-035 (the vendor fix for this issue) to all affected Windows 2000, XP and Server 2003 systems.
  • Block inbound SMB (TCP 445 and 139) at network boundaries and restrict it to trusted internal segments.
  • Disable the Server service on hosts that do not need to share files or printers.
  • Retire or isolate unsupported Windows 2000/XP/Server 2003 systems that cannot be patched.
  • Monitor for anomalous SMB traffic from untrusted sources as a compensating control.

Detection

  • Inspect SMB traffic for malformed or unusual requests targeting the Server Service, especially from unexpected external hosts.
  • Alert on SMB connections to port 445/139 originating outside trusted network ranges.
  • Review host logs for Server Service errors or crashes that could accompany crafted SMB requests.
  • Track unpatched Windows 2000/XP/Server 2003 hosts still exposing SMB on the network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-1315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2006-1315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.