Impact
A null pointer dereference in the Windows IKE Extension can be triggered by an unauthorized attacker over the network. The flaw causes the extension to crash or become unresponsive, resulting in a denial of service. No information disclosure, data alteration, or privilege escalation is described; the impact is limited to service availability.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the null pointer dereference by sending crafted IKE traffic over the network without any special privileges, leading to service disruption.
OpenCVE Enrichment