Executive brief
A vulnerability exists in the Windows Internet Key Exchange (IKE) protocol, which is used to set up secure connections like VPNs. An unauthorized attacker can exploit this flaw over the network to crash the affected system, leading to a denial of service. This can disrupt remote access and secure communications for the entire organization.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Microsoft Windows Internet Key Exchange (IKE) protocol implementation. The vulnerability can be triggered by a remote, unauthenticated attacker sending specially crafted packets over the network. Successful exploitation allows the attacker to cause a denial-of-service (DoS) condition by crashing the target system. The issue affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.