Executive brief
Windows Internet Connection Sharing (ICS) is a built-in Windows feature that allows computers to share network connectivity with other devices. A missing authentication check in a critical ICS function allows an authorized local attacker to tamper with network sharing settings and configurations, potentially disrupting network connectivity or enabling unauthorized access to shared resources.
Technical details
The vulnerability is an authentication bypass in Windows Internet Connection Sharing (ICS) due to missing authentication checks on a critical function. The flaw is exploitable by an attacker with local system access; no network access or elevated privileges are required beyond local access. An attacker can exploit this to tamper with ICS configurations and settings. The vulnerability is tracked as CVE-2026-72964 with a CVSS score of 5.5 (medium severity). A security patch has been released by Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed