Impact
A heap‑based buffer overflow in the Windows IKE Extension permits an authorized attacker to execute arbitrary code over a network. The overflow occurs because the protocol fails to validate the length of IKE Extension data, allowing the attacker to corrupt heap memory and execute arbitrary code; based on the description it appears this is due to insufficient bounds checking. The impact includes compromise of confidentiality, integrity, and availability on the affected system.
Affected Systems
Affected Windows operating systems include Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2019, 2022, 2025, across all supported architectures (x86, x64, arm64).
Risk and Exploitability
The CVSS score of 7.5 reflects high severity, while the EPSS score is <1% and the vulnerability is not listed in CISA KEV. The attack requires a network‑accessible IKE service and enables an authorized attacker—one with legitimate credentials or administrative privileges—to send specially crafted packets that cause the overflow, leading to remote code execution. This makes the flaw a high‑priority patching target, though exploitation likelihood remains low based on current EPSS data.
OpenCVE Enrichment