Junglewise Threat Intelligence

CVE-2026-40405: Microsoft Windows null pointer dereference in TCP/IP stack

CVE-2026-40405 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A vulnerability exists in the core networking component of the Microsoft Windows operating system. An unauthorized attacker can exploit this flaw over a network to cause the system to crash or become unresponsive. This results in a denial-of-service condition, potentially disrupting business operations and server availability without requiring any user interaction.

Technical details

This vulnerability is classified as a NULL pointer dereference (CWE-476) within the Windows TCP/IP stack. The flaw is triggered when the networking stack improperly handles specifically crafted network packets, leading to a system crash (Blue Screen of Death). The attack vector is network-based and requires no prior authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation results in a complete loss of availability for the affected system. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD publication.

References

Related threats