Executive brief
Windows IKE Extension is a network security component that handles encrypted connections over IP networks. A null pointer dereference vulnerability allows a remote attacker to crash the affected system and cause a denial of service, disrupting network communications and requiring manual intervention to restore service.
Technical details
A null pointer dereference vulnerability exists in Microsoft Windows IKE Extension that can be triggered by a network-based attacker without authentication. The vulnerability allows an attacker to send specially crafted network packets that cause the IKE extension to dereference a null pointer, resulting in a denial of service condition. The affected component is reachable over the network and does not require user interaction. An attacker can repeatedly trigger this crash to sustain a denial of service attack against the target system. Patches are expected from Microsoft as part of standard security updates.
Affected products
- Microsoft Windows IKE Extension
Timeline
- 2026-09-08: disclosed