ZeroHour

CVE-2026-69587

mass

Unauthenticated DoS via Null Pointer Dereference in Windows IKE Extension

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-69587 is a null pointer dereference (CWE-476) in the Windows IKE Extension, the in-box Windows component that performs Internet Key Exchange (IKE) negotiation for IPsec/VPN connections. An unauthenticated remote attacker can trigger the flaw by sending crafted IKE packets over the network, with no credentials or user interaction required. Successful exploitation crashes the IKE Extension service, resulting in denial of service only; the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) confirms no confidentiality or integrity impact. Affected systems are Windows machines running and network-reachable via the IKE Extension, though the available data does not enumerate specific affected Windows editions or builds. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 1.2% probability of exploitation within 30 days (66th percentile), so no in-the-wild exploitation is currently known.

What to do: Apply Microsoft's security update for CVE-2026-69587 when published, checking the Microsoft advisory for the affected editions, which were not enumerated in this data. As an interim mitigation, restrict IKE traffic (UDP ports 500 and 4500) at network boundaries to trusted peers and verify whether the IKEEXT service is running and reachable on exposed hosts. The impact is availability-only and services typically recover after a crash, but an attacker can re-trigger the condition with repeated packets, so prioritized patching of VPN/IPsec-exposed systems is recommended.

Affected
Microsoft Windows IKE Extension
Estimated exposure
massmass-scale: >1M Windows devices ship the in-box IKE Extension, with practical DoS exposure on the order of 100k-1M+ hosts where IKE traffic is network-reachable — Estimated from Windows' ~1.4-billion-device install base, since the IKE Extension ships in-box with Windows, while practical exposure is limited to systems where IKE packets (UDP 500/4500) can reach the host, which is common in enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.