CVE-2026-69588
mass1Memory Leak Denial-of-Service in Windows TCP/IP
CVE-2026-69588 is a memory handling flaw (CWE-401, missing release of memory after its effective lifetime) in the Microsoft Windows TCP/IP network stack. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a vulnerable Windows system, causing memory that is no longer in use to not be released. Repeated triggering can exhaust system resources and yield a high-impact denial of service; confidentiality and integrity are not affected. Any Windows system running the TCP/IP stack is affected — the specific Windows versions in scope were not enumerated in the source data and should be taken from Microsoft's advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at 1.2%, so no confirmed in-the-wild exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-69588 to all Windows systems, prioritizing internet-exposed servers, VPN/RDP gateways, and other network-facing hosts where a remote DoS is most disruptive. Because there is no public PoC or KEV entry, a routine patch-cycle approach is defensible, but watch exposed systems for network-stack memory growth, service hangs, or unexplained reboots. Restricting reachability of vulnerable hosts (firewalling, reduced attack surface) provides interim mitigation until patching completes.
| Microsoft Windows (TCP/IP network stack) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-401
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.