Executive brief
Windows TCP/IP, a core networking component used to enable all network communication on Windows systems, contains a memory safety vulnerability that can allow an authorized attacker to gain elevated privileges over the network. This could lead to unauthorized system-level access and complete compromise of an affected computer.
Technical details
A use-after-free vulnerability exists in the Windows TCP/IP stack that can be exploited by an authorized attacker to achieve privilege escalation. The vulnerability requires network access and an authenticated user context to exploit. An attacker who successfully exploits this vulnerability can execute code with elevated privileges (SYSTEM level), leading to complete system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Windows TCP/IP <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- other: Not reported exploited in wild as of disclosure date