Junglewise Threat Intelligence

CVE-2026-70575: Microsoft Windows Schannel null pointer dereference

CVE-2026-70575 · Severity: medium · CVSS 5.3 · Published 2026-09-08

Executive brief

Windows Schannel is the cryptographic protocol handler that secures network communications for Windows systems, including HTTPS connections and remote access services. A null pointer dereference vulnerability allows an authorized attacker to crash the Schannel service, disrupting secure network communications and potentially causing denial of service to dependent applications and services.

Technical details

A null pointer dereference vulnerability exists in Windows Schannel's handling of TLS/SSL protocol operations. An authorized attacker can trigger this vulnerability over the network by sending specially crafted requests to a system running the affected Schannel implementation. Exploitation results in a crash of the Schannel service, causing denial of service to applications that depend on it for secure communications. The vulnerability requires network connectivity and authorization, but does not allow code execution or data theft. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Windows (Schannel) <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats