ZeroHour

CVE-2026-69793

mass

Remote Security Feature Bypass in Microsoft Windows TCP/IP

CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-69793 is a flaw in the Windows TCP/IP networking stack in which input is not properly validated for internal consistency (CWE-1288), allowing a security feature to be bypassed. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a vulnerable Windows host; per the CVSS vector, no privileges or user interaction are required. Successful exploitation compromises integrity only: the attacker bypasses a Windows security feature, with no confidentiality or availability impact per the CVSS score. Any Windows system using the TCP/IP stack is potentially affected, which in practice means essentially all Windows desktops and servers, with the exact affected builds listed in Microsoft's advisory. As of this analysis there is no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation, and EPSS estimates a 0.8% probability of exploitation within 30 days.

What to do: Check Microsoft's security advisory for the exact affected and fixed builds and apply the corresponding Windows security update as soon as feasible. Because the flaw is remotely triggerable without authentication, prioritize patching internet-facing Windows hosts (servers exposing RDP, VPN, or other network services). There is no practical workaround for the TCP/IP stack and no known PoC or in-the-wild exploitation, so patching is the primary and only effective mitigation.

Affected
Microsoft Windows TCP/IP (component of Microsoft Windows client and server operating systems)
Estimated exposure
mass1 billion+ Windows devices (the TCP/IP stack is present in every Windows installation; millions of internet-exposed Windows hosts appear in public scans) — The TCP/IP stack ships in every Windows client and server, and Windows runs on well over a billion devices with millions of Windows hosts routinely observed exposed to the internet in public scan data, so the plausible affected population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.

Weakness
CWE-1288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.