Impact
This vulnerability is a double free flaw in the Windows Internet Key Exchange (IKE) Service Extensions, identified as CWE‑415. A double free can corrupt memory and allow an attacker to execute arbitrary code on the target system. The impact is full compromise, granting malicious control over the affected machine’s data and operational capabilities.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 22H3, 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, 2025, and 23H2, including Server Core installations are affected by this flaw.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalogue. It is inferred that an attacker can trigger the double free by sending specially crafted IKE packets over the network, enabling remote code execution without authentication. The high severity and remote exploitation potential warrant immediate action to protect vulnerable systems.
OpenCVE Enrichment