ZeroHour

CVE-2026-69429

mass

Heap Buffer Overflow in Windows IKE Extension Enables Authenticated RCE

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-69429 is a heap-based buffer overflow (CWE-122) in the Windows IKE Extension, the Windows component that performs IKEv2/IPsec key negotiation for VPN and IPsec connectivity. An authorized attacker with low privileges can trigger the flaw by sending crafted network traffic to the IKE extension; no user interaction is required, though the attack complexity is rated high. Successful exploitation yields remote code execution in the context of the IKEEXT service, with high impact on confidentiality, integrity, and availability. Any environment running Windows systems whose IKE extension is reachable over the network is potentially affected. There is currently no known exploitation in the wild, no public proof-of-concept, the flaw is not on CISA's KEV list, and EPSS estimates roughly a 0.6% chance of exploitation within 30 days.

What to do: Check Microsoft's advisory for the fixed builds and apply the update via Windows Update as soon as it is released (no fixed version numbers are listed in the source data). Until patching, restrict inbound UDP 500 and 4500 (IKE/IPsec NAT-T) at network boundaries to trusted VPN peers and identify internet-reachable Windows hosts with the IKEEXT service running. Because the flaw requires authorized access, review which accounts or devices can reach IKE endpoints and monitor for anomalous IKEEXT crashes or restarts.

Affected
Microsoft Windows IKE Extension (IKE and AuthIP IPsec Keying Modules service)
Estimated exposure
masshundreds of millions of Windows endpoints ship the IKEEXT service by default (actual remotely exploitable subset far smaller, since exploitation requires… — The IKE and AuthIP IPsec Keying Modules service ships as a standard Windows component across Windows client and server editions, whose combined installed base is in the hundreds of millions, so the upper-bound exposure is mass-scale even…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.