CVE-2026-69429
massHeap Buffer Overflow in Windows IKE Extension Enables Authenticated RCE
CVE-2026-69429 is a heap-based buffer overflow (CWE-122) in the Windows IKE Extension, the Windows component that performs IKEv2/IPsec key negotiation for VPN and IPsec connectivity. An authorized attacker with low privileges can trigger the flaw by sending crafted network traffic to the IKE extension; no user interaction is required, though the attack complexity is rated high. Successful exploitation yields remote code execution in the context of the IKEEXT service, with high impact on confidentiality, integrity, and availability. Any environment running Windows systems whose IKE extension is reachable over the network is potentially affected. There is currently no known exploitation in the wild, no public proof-of-concept, the flaw is not on CISA's KEV list, and EPSS estimates roughly a 0.6% chance of exploitation within 30 days.
What to do: Check Microsoft's advisory for the fixed builds and apply the update via Windows Update as soon as it is released (no fixed version numbers are listed in the source data). Until patching, restrict inbound UDP 500 and 4500 (IKE/IPsec NAT-T) at network boundaries to trusted VPN peers and identify internet-reachable Windows hosts with the IKEEXT service running. Because the flaw requires authorized access, review which accounts or devices can reach IKE endpoints and monitor for anomalous IKEEXT crashes or restarts.
| Microsoft Windows IKE Extension (IKE and AuthIP IPsec Keying Modules service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.