Denial of Service Vulnerability in Windows Internet Key Exchange Protocol
CVE-2026-35424
7.5HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-35424?
A significant vulnerability exists in the Windows Internet Key Exchange (IKE) Protocol due to the improper release of memory after its effective lifetime, potentially enabling an unauthorized attacker to disrupt service on a network. This breach can lead to denial of service attacks, allowing malicious actors to hinder the normal operations of the affected service, impacting usability and security.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291