CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-42904

CVSS 9.6v3.1pub. 2026-06-09upd. 2026-06-11

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

🤖 AI Analysis
How it works

The CWE-122 class error (heap-based buffer overflow) involves writing data outside the boundaries of a buffer allocated on the heap within the Windows TCP/IP component. An attacker located on the same local network (network vector: adjacent) can send specially crafted network packets that cause buffer overflow. As a result, it is possible to overwrite critical data structures in kernel memory or user space and take control of code execution with elevated privileges.

Impact

Successful exploitation of the vulnerability allows an attacker to perform privilege escalation — obtaining elevated privileges on the target system, which consequently may lead to complete takeover of the machine, violation of data confidentiality and integrity, and disruption of system availability.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904. Until the patch is deployed, it is recommended to restrict access to vulnerable systems from the local network by implementing network segmentation and access control at the firewall level.

Who is affected

Windows systems with the TCP/IP component — versions indicated in the manufacturer's references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Windows 10 21h2

    OS
    Microsoft
    < 10.0.19044.7417
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    < 10.0.19045.7417
  • Microsoft Windows 11 23h2

    OS
    Microsoft
    < 10.0.22631.7219
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.8655
  • Microsoft Windows 11 25h2

    OS
    Microsoft
    < 10.0.26200.8655
  • Microsoft Windows 11 26h1

    OS
    Microsoft
    < 10.0.28000.2269
  • Microsoft Windows Server 2022

    OS
    Microsoft
    < 10.0.20348.5256
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.32995
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2026-62878CRITICAL9.8same product

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-62815CRITICAL9.8same product

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVE-2026-62893CRITICAL9.8same product

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.