Impact
The vulnerability is caused by improper validation of consistency within network input data in the Windows TCP/IP stack. This flaw allows an attacker to send specially crafted packets that cause the operating system to treat the data as legitimate, effectively bypassing a built‑in security feature. The issue is identified as CWE‑1288, which involves failing to validate consistency of input across contexts.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.5 denotes a medium‑high severity, indicating that exploitation could have significant impact. The EPSS score is not available, so the current likelihood of real‑world exploitation cannot be quantified from the available data. The vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been reported. The likely attack vector is a remote attacker sending crafted network packets to a target system running one of the affected Windows releases.
OpenCVE Enrichment