Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
The CWE-122 class error (heap-based buffer overflow) involves writing data outside the boundaries of a buffer allocated on the heap within the Windows TCP/IP component. An attacker located on the same local network (network vector: adjacent) can send specially crafted network packets that cause buffer overflow. As a result, it is possible to overwrite critical data structures in kernel memory or user space and take control of code execution with elevated privileges.
Successful exploitation of the vulnerability allows an attacker to perform privilege escalation — obtaining elevated privileges on the target system, which consequently may lead to complete takeover of the machine, violation of data confidentiality and integrity, and disruption of system availability.
Apply patches available from the manufacturer according to the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904. Until the patch is deployed, it is recommended to restrict access to vulnerable systems from the local network by implementing network segmentation and access control at the firewall level.
Windows systems with the TCP/IP component — versions indicated in the manufacturer's references (Microsoft Security Response Center).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HMicrosoft Windows 10 21h2
OSMicrosoft< 10.0.19044.7417Microsoft Windows 10 22h2
OSMicrosoft< 10.0.19045.7417Microsoft Windows 11 23h2
OSMicrosoft< 10.0.22631.7219Microsoft Windows 11 24h2
OSMicrosoft< 10.0.26100.8655Microsoft Windows 11 25h2
OSMicrosoft< 10.0.26200.8655Microsoft Windows 11 26h1
OSMicrosoft< 10.0.28000.2269Microsoft Windows Server 2022
OSMicrosoft< 10.0.20348.5256Microsoft Windows Server 2025
OSMicrosoft< 10.0.26100.32995
Related vulnerabilities
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
RCE w Windows Server Update Service (WSUS) — deserializacja danych
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.