Junglewise Threat Intelligence

CVE-2026-40401: Microsoft Windows TCP/IP denial of service via null pointer dereference

CVE-2026-40401 · Severity: high · CVSS 7.1 · Published 2026-05-12

Technologies: Microsoft Windows 11, Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows networking component could allow an attacker to crash a system, leading to a total loss of availability. This affects a wide range of Windows desktop and server operating systems. While the attack must be initiated locally, it can result in a blue screen or system reboot, disrupting business operations and services.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in the Windows TCP/IP stack. An unauthorized attacker can exploit this flaw locally to trigger a system crash (Denial of Service). The vulnerability is characterized by a CVSS 3.1 score of 7.1, notably featuring a Scope change (S:C), which often indicates the impact extends beyond the immediate vulnerable component to the entire operating system. Microsoft has released security updates to address this issue across supported versions of Windows 10, 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, 23H2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats