Junglewise Threat Intelligence

CVE-2026-40406: Microsoft Windows use after free in TCP/IP stack

CVE-2026-40406 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows networking component (TCP/IP) that allows an unauthorized person to access sensitive information over a network. This component is responsible for how the computer communicates with other devices on the internet or local network. An attacker could exploit this to view data they are not authorized to see, potentially compromising privacy or corporate secrets.

Technical details

A use-after-free (UAF) vulnerability exists within the Microsoft Windows TCP/IP stack, identified as CWE-416. The flaw is triggered when the system attempts to access memory that has already been deallocated during the processing of network packets. An unauthenticated attacker can exploit this over the network without any user interaction. Successful exploitation allows for unauthorized information disclosure, potentially leaking kernel memory or other sensitive data to the attacker. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows All supported versions

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats