Remote Code Execution Vulnerability in Windows IKE Service Extensions
CVE-2026-33824

9.8CRITICAL

What is CVE-2026-33824?

A vulnerability exists in the Windows Internet Key Exchange (IKE) Service Extensions that allows an attacker to exploit a double free condition. This flaw can lead to remote code execution, permitting unauthorized users to execute arbitrary code over a network. Proper mitigation and timely patches are crucial for safeguarding systems against this vulnerability.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9060

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8644

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7184

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.