Impact
A null pointer dereference in Windows TCP/IP allows an attacker to cause a denial of service when the vulnerable system receives a specially crafted packet. The flaw does not provide any gain in confidentiality or integrity; the attacker’s benefit is to interrupt services or disrupt network communication for the affected host. The weakness corresponds to CWE‑476, reflecting an improper null pointer dereference that may be triggered by malformed network traffic.
Affected Systems
The vulnerability impacts a wide range of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and the Windows Server family from 2012 up through the 2025 releases. All architectures listed in the CPE data (x86, x64, arm64) are affected. Users running any of these supported editions should verify whether they have applied the security update that addresses CVE‑2026‑59132.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity chance of disruption. The EPSS score of 1% signals that while exploitation potential is low, the attack might still occur on high‑profile targets. Because the flaw exists in the TCP/IP stack, an attacker may only need network reachability to send the crafted packet; no local privileges are required. The vulnerability is not yet listed in the CISA KEV catalog, but the high CVSS score and the possibility of remote exploitation make it a significant risk for any exposed Windows host.
OpenCVE Enrichment