Executive brief
Windows IKE (Internet Key Exchange) Extension is a component that handles encryption protocols for VPN and network communications. A heap-based buffer overflow in this component could allow an authorized attacker to execute arbitrary code on affected systems, potentially compromising network infrastructure and sensitive communications.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Windows IKE Extension. The vulnerability can be exploited by an authorized attacker to execute arbitrary code over the network. The attack requires network connectivity and prior authorization, but no user interaction is needed. Successful exploitation could lead to remote code execution with the privileges of the IKE service. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Windows IKE Extension <UNKNOWN>
Timeline
- 2026-09-08: disclosed