Impact
Missing release of memory after its intended lifetime in the Windows TCP/IP stack enables an unauthenticated attacker to send specially crafted packets that keep resources allocated. The flaw causes a gradual exhaustion of network‑layer memory, eventually rendering the affected system unable to process normal network traffic. The vulnerability leads solely to a denial of service; it provides no code execution or privilege escalation path.
Affected Systems
The flaw affects Microsoft Windows 11 across versions 23H2, 24H2, 25H2, and 26H1, and Windows Server 2022 and Windows Server 2025, including the Server Core installation.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. The EPSS score of 1% suggests a low but non‑negligible probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over a network: an unauthenticated attacker can send specially crafted TCP/IP packets to trigger the memory leak, potentially affecting any exposed system at remote sites.
OpenCVE Enrichment