Executive brief
A vulnerability in the Windows networking stack could allow an attacker on the same local network to crash a computer or server. This affects the core component responsible for internet and network communications (TCP/IP). An exploit would result in a blue screen or system reboot, causing an immediate service outage and potential data loss for unsaved work.
Technical details
A NULL pointer dereference (CWE-476) exists within the Windows TCP/IP stack. An unauthenticated attacker located on the same local network or subnet (adjacent vector) can trigger this vulnerability by sending specially crafted network traffic. Successful exploitation results in a system crash (Bug Check), leading to a Denial of Service (DoS) condition. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2012 through 2025. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, 23H2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security advisory and update guide.
- 2026-06-01: other: NVD record modified after enrichment.