Executive brief
A vulnerability exists in the Windows TCP/IP networking component, which handles how the computer communicates over a network. An authorized user on the same local network could exploit this flaw to crash the system, leading to a denial of service. This could disrupt business operations by forcing affected computers to restart or become unresponsive.
Technical details
A denial of service vulnerability exists in the Windows TCP/IP stack due to an incorrect calculation of buffer size (CWE-131). To exploit this, an attacker must be authenticated and located on the same adjacent network as the target. By sending specially crafted network traffic, the attacker can trigger a system crash or hang. The vulnerability is rated with a CVSS 3.1 score of 5.7, reflecting high impact on availability but no impact on confidentiality or integrity. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed: Initial publication of CVE-2026-42915 by Microsoft.
- 2026-06-09: advisory: Microsoft Security Response Center advisory published.