Junglewise Threat Intelligence

CVE-2026-35422: Microsoft Windows TCP/IP authentication bypass

CVE-2026-35422 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A security flaw in the Windows networking component could allow an authorized user to bypass certain security protections. This component is responsible for how the computer communicates over the internet and local networks. If exploited, an attacker who already has basic access to the network could circumvent security controls, potentially leading to unauthorized actions or data manipulation.

Technical details

This vulnerability (CWE-288) exists in the Windows TCP/IP stack and involves an authentication bypass using an alternate path or channel. An attacker with low-level privileges (PR:L) can exploit this over the network without user interaction. The root cause is a failure to properly enforce security controls across all communication paths within the networking stack. Successful exploitation allows the attacker to bypass intended security features, though it does not directly result in data confidentiality loss or service downtime according to the CVSS vector. Microsoft has released information regarding this via their Security Update Guide.

Affected products

  • Microsoft Windows TCP/IP Stack

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats