Yeah, only the username. Still, that seems like a pretty hard thing to blind guess at in most attack scenarios if you can't get it through the cifs connect. My reading is that you couldn't brute force it, you'd have one chance to set up the iframe with the cookie file in it which needs the username, or at least just one chance per clickjacked drag action that the user executes for you.
If it's a targeted attack I suppose you have a better shot, are most home windows user names set to the user's full name like "John Doe"?