ZeroHour

CVE-2026-69588

mass1

Memory Leak Denial-of-Service in Windows TCP/IP

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-69588 is a memory handling flaw (CWE-401, missing release of memory after its effective lifetime) in the Microsoft Windows TCP/IP network stack. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a vulnerable Windows system, causing memory that is no longer in use to not be released. Repeated triggering can exhaust system resources and yield a high-impact denial of service; confidentiality and integrity are not affected. Any Windows system running the TCP/IP stack is affected — the specific Windows versions in scope were not enumerated in the source data and should be taken from Microsoft's advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at 1.2%, so no confirmed in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-69588 to all Windows systems, prioritizing internet-exposed servers, VPN/RDP gateways, and other network-facing hosts where a remote DoS is most disruptive. Because there is no public PoC or KEV entry, a routine patch-cycle approach is defensible, but watch exposed systems for network-stack memory growth, service hangs, or unexplained reboots. Restricting reachability of vulnerable hosts (firewalling, reduced attack surface) provides interim mitigation until patching completes.

Affected
Microsoft Windows (TCP/IP network stack)
Estimated exposure
mass≈1 billion+ Windows devices (TCP/IP stack ships in every Windows installation) — Microsoft has publicly reported over 1.4 billion monthly active Windows 10/11 devices, and the TCP/IP stack is present in all Windows installs, so the theoretical exposure is effectively the entire Windows installed base; practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.