Executive brief
Microsoft's Internet Key Exchange (IKE) service, used to establish secure VPN and encrypted network connections, contains a critical memory management flaw. An attacker on the network can send a malicious packet to trigger the vulnerability, allowing them to execute arbitrary code with system-level privileges. This vulnerability is currently being exploited by threat actors in active attacks.
Technical details
A double free vulnerability exists in Microsoft Internet Key Exchange Service Extensions, where the same memory region is freed twice during packet processing. This memory corruption flaw can be triggered remotely by sending a specially crafted IKE protocol packet without requiring authentication. An attacker can leverage the double free to corrupt the heap, achieve arbitrary code execution, and potentially gain system-level privileges on the affected machine. The vulnerability is actively being exploited in real-world attacks.
Affected products
- Microsoft Internet Key Exchange Service Extensions
Timeline
- 2026-08-18: disclosed
- exploited: Reported exploited in wild