Impact
The vulnerability is a null pointer dereference in the Windows Internet Key Exchange (IKE) Extension. An attacker can trigger the fault through specially crafted network traffic, causing the IKE service to terminate and resulting in a denial of service for all IPsec or VPN connections that rely on that service. This flaw falls under CWE-476 and disrupts connectivity rather than exposing data directly.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 (both ARM64 and x64) and Microsoft Windows Server 2022 and 2025, including the server‑core installations, are affected by this flaw. It exists in any build that includes the IKE Extension feature.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderately high severity, but the EPSS score of 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog, indicating that large‑scale exploitation has not yet been observed. Based on the description, the likely attack vector is remote network access to IKE traffic; an adversary can trigger the denial of service by sending abnormal packets to the IKE service from a host on the same LAN or from the Internet if the service is exposed. This poses a risk to organizations that run unattended VPN or IPsec servers.
OpenCVE Enrichment