CVE-2006-1315 describes an information disclosure vulnerability in the Server Service (SRV.SYS driver) affecting Microsoft Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1. Remote attackers can exploit this by sending crafted requests that cause uninitialized SMB buffers to leak sensitive information. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it is a medium-severity vulnerability, indicating low attack complexity and potential for partial confidentiality impact without requiring authentication. While the EPSS score is high, suggesting potential exploitability, there is no evidence of active exploitation, no known Metasploit or Nuclei modules, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:server_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
Jul 11, 2006Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
Jul 11, 2006Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
Jul 11, 2006Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
Jul 11, 2006