Executive brief
A vulnerability in the Windows Network Controller Host Agent could allow a user with basic access to a system to crash the service. This component is responsible for managing network infrastructure in software-defined networking environments. An exploit would result in a local denial-of-service, potentially disrupting network management operations on the affected host.
Technical details
This vulnerability is classified as a use-after-free (CWE-416) and untrusted pointer dereference (CWE-822) within the Windows Network Controller (NC) Host Agent. An attacker with low-privileged local access can trigger the flaw without any user interaction. The root cause involves the service attempting to use a memory pointer after it has been freed or improperly validated, leading to a crash of the host agent. Successful exploitation results in a loss of availability for the affected component. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Network Controller (NC) Host Agent
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory