Junglewise Threat Intelligence

CVE-2026-42904: Microsoft Windows heap overflow in TCP/IP stack

CVE-2026-42904 · Severity: critical · CVSS 9.6 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Windows TCP/IP networking component, which handles how the computer communicates over a network. An attacker located on the same local network (such as the same Wi-Fi or office network) could exploit this flaw to gain full control over a vulnerable system without needing any user interaction or login credentials. This could lead to a total compromise of the affected machine, including data theft or the installation of malicious software.

Technical details

This vulnerability is a heap-based buffer overflow (CWE-122) residing within the Windows TCP/IP stack. The flaw can be triggered by an unauthenticated attacker located on the same local network segment (adjacent) by sending specially crafted network packets. Because the vulnerability exists in the kernel-mode networking driver, successful exploitation allows for remote code execution with elevated privileges, potentially leading to a full system takeover. The CVSS 3.1 score of 9.6 reflects the high impact on confidentiality, integrity, and availability, as well as the lack of required user interaction or authentication. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed: CVE record published by Microsoft and NVD.
  • 2026-06-09: advisory: Microsoft released the Security Update Guide for this vulnerability.

References