Executive brief
A security vulnerability exists in the Windows networking component responsible for handling internet traffic. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows TCP/IP stack. The flaw is triggered when the component improperly handles memory allocation for network data, leading to memory corruption. An attacker must have local access and low-level user privileges to execute a specially crafted application that triggers the overflow. Successful exploitation allows the attacker to bypass security boundaries and execute code with SYSTEM privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory