CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2026-33824

CVSS 9.8v3.1pub. 2026-04-14upd. 2026-08-18

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The double free vulnerability (CWE-415) consists of freeing the same memory area twice by the vulnerable component. An attacker can send specially crafted network packets to the IKE Extension service, causing heap corruption. This allows the attacker to take control over the process execution flow and execute arbitrary code in the context of the vulnerable service, without the need for any privileges or user interaction.

Impact

An unauthenticated remote attacker can remotely execute arbitrary code on a vulnerable system, which may lead to complete system takeover, disclosure of sensitive data, or disruption of its availability.

Mitigation & patch

Security patches available from the vendor should be applied according to references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824). Additionally, it is recommended to restrict network access to IKE services (UDP ports 500 and 4500) only to trusted hosts using firewall rules, as a temporary measure until the patch is deployed.

Who is affected

Microsoft Windows 10 22H2, Microsoft Windows 11 23H2, Microsoft Windows 11 26H1, Microsoft Windows Server 2022, Microsoft Windows Server 2022 23H2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Windows 10 1607

    OS
    Microsoft
    < 10.0.14393.9060
  • Microsoft Windows 10 1809

    OS
    Microsoft
    < 10.0.17763.8644
  • Microsoft Windows 10 21h2

    OS
    Microsoft
    < 10.0.19044.7184
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    < 10.0.19045.7184
  • Microsoft Windows 11 23h2

    OS
    Microsoft
    < 10.0.22631.6936
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.8246
  • Microsoft Windows 11 25h2

    OS
    Microsoft
    < 10.0.26200.8246
  • Microsoft Windows 11 26h1

    OS
    Microsoft
    < 10.0.28000.1836
  • Microsoft Windows Server 2016

    OS
    Microsoft
    < 10.0.14393.9060
  • Microsoft Windows Server 2019

    OS
    Microsoft
    < 10.0.17763.8644
  • Microsoft Windows Server 2022

    OS
    Microsoft
    < 10.0.20348.5020
  • Microsoft Windows Server 2022 23h2

    OS
    Microsoft
    < 10.0.25398.2274
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.32690

CISA KEV — detailsi

Vendori
Microsoft
Producti
Internet Key Exchange (IKE) Service Extensions
Added to KEVi
August 18, 2026
Remediation deadline (US Federal)i
August 21, 2026(overdue)
Required action (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA descriptioni

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 21 sierpnia 2026
CWE
References

Related vulnerabilities

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product

RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)

CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product

RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych

CVE-2017-8543CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Search — przejęcie kontroli nad systemem