Junglewise Threat Intelligence

CVE-2026-40413: Microsoft Windows TCP/IP null pointer dereference denial of service

CVE-2026-40413 · Severity: high · CVSS 7.4 · Published 2026-05-12

Technologies: Microsoft Windows 11, Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows networking stack could allow an attacker to crash a computer or server remotely. This affects the core component responsible for internet and network communications (TCP/IP) across most modern versions of Windows and Windows Server. An exploit would result in a blue screen or system reboot, causing an immediate service outage for the affected machine.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists within the Windows TCP/IP protocol driver. An unauthenticated attacker can exploit this flaw by sending specially crafted network packets over an adjacent network (Layer 2 proximity). Successful exploitation results in a kernel-mode crash (Bug Check), leading to a complete denial of service for the target system. The vulnerability affects a wide range of Windows client and server versions, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, 23H2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats