Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
The double free vulnerability (CWE-415) consists of freeing the same memory area twice by the vulnerable component. An attacker can send specially crafted network packets to the IKE Extension service, causing heap corruption. This allows the attacker to take control over the process execution flow and execute arbitrary code in the context of the vulnerable service, without the need for any privileges or user interaction.
An unauthenticated remote attacker can remotely execute arbitrary code on a vulnerable system, which may lead to complete system takeover, disclosure of sensitive data, or disruption of its availability.
Security patches available from the vendor should be applied according to references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824). Additionally, it is recommended to restrict network access to IKE services (UDP ports 500 and 4500) only to trusted hosts using firewall rules, as a temporary measure until the patch is deployed.
Microsoft Windows 10 22H2, Microsoft Windows 11 23H2, Microsoft Windows 11 26H1, Microsoft Windows Server 2022, Microsoft Windows Server 2022 23H2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 10 1607
OSMicrosoft< 10.0.14393.9060Microsoft Windows 10 1809
OSMicrosoft< 10.0.17763.8644Microsoft Windows 10 21h2
OSMicrosoft< 10.0.19044.7184Microsoft Windows 10 22h2
OSMicrosoft< 10.0.19045.7184Microsoft Windows 11 23h2
OSMicrosoft< 10.0.22631.6936Microsoft Windows 11 24h2
OSMicrosoft< 10.0.26100.8246Microsoft Windows 11 25h2
OSMicrosoft< 10.0.26200.8246Microsoft Windows 11 26h1
OSMicrosoft< 10.0.28000.1836Microsoft Windows Server 2016
OSMicrosoft< 10.0.14393.9060Microsoft Windows Server 2019
OSMicrosoft< 10.0.17763.8644Microsoft Windows Server 2022
OSMicrosoft< 10.0.20348.5020Microsoft Windows Server 2022 23h2
OSMicrosoft< 10.0.25398.2274Microsoft Windows Server 2025
OSMicrosoft< 10.0.26100.32690
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Internet Key Exchange (IKE) Service Extensions
- Added to KEVi
- August 18, 2026
- Remediation deadline (US Federal)i
- August 21, 2026(overdue)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Related vulnerabilities
RCE w Windows Server Update Service (WSUS) — deserializacja danych
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych
RCE w Windows Search — przejęcie kontroli nad systemem