Junglewise Threat Intelligence

CVE-2026-35424: Microsoft Windows IKE Protocol memory leak denial of service

CVE-2026-35424 · Severity: high · CVSS 7.5 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Internet Key Exchange (IKE) protocol, which is used to set up secure, encrypted connections between devices. An unauthorized attacker can exploit this flaw over the network to cause a system to run out of memory, leading to a denial-of-service condition. This could disrupt secure communications and impact the availability of affected Windows systems.

Technical details

A memory leak vulnerability (CWE-401) exists in the Microsoft Windows Internet Key Exchange (IKE) Protocol implementation. The flaw is caused by the missing release of memory after its effective lifetime during protocol operations. A remote, unauthenticated attacker can exploit this by sending specially crafted network packets to a vulnerable system. Successful exploitation leads to memory exhaustion, resulting in a denial-of-service (DoS) state where the system or service becomes unresponsive. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Internet Key Exchange (IKE) Protocol

Timeline

  • 2026-05-12: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-05-12: advisory: Microsoft Security Update Guide published.

References