Denial of Service Vulnerability in Windows Network Controller by Microsoft
CVE-2026-44805

5.5MEDIUM

What is CVE-2026-44805?

A vulnerability in the Windows Network Controller (NC) Host Agent could allow an authorized attacker to execute a denial of service attack locally, impacting the stability of the affected service. This 'use after free' flaw can lead to unexpected behavior and service interruptions.

Affected Version(s)

Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.8880

Windows Server 2019 x64-based Systems 10.0.17763.0 < 10.0.17763.8880

Windows Server 2022 x64-based Systems 10.0.20348.0 < 10.0.20348.5256

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.