AI analysis
CVE-2026-72983 is a use-after-free memory-safety flaw (CWE-416) in the Windows Internet Connection Sharing (ICS) component, rated Critical (CVSS 9.8) because it is reachable over the network by an unauthenticated attacker with no user interaction. It is triggered by sending crafted network traffic to a Windows host running ICS — for example a machine sharing its connection or acting as a gateway/hotspot — causing the service to use memory that has already been freed. A successful attack lets the adversary execute arbitrary code on the affected host, giving full confidentiality, integrity and availability impact (C:H/I:H/A:H). Affected are Windows systems on which ICS is enabled and network-reachable; specific Windows version ranges are not provided in the source data, and Microsoft shipped the fix in its September 2026 security updates. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists yet; EPSS puts the 30-day exploitation probability at 0.9% (58th percentile).
What to do: Apply Microsoft's September 2026 security updates on all Windows systems, prioritizing hosts that have Internet Connection Sharing or the mobile hotspot feature enabled or that sit on untrusted/exposed network segments. Where ICS is not needed, disable the SharedAccess service and restrict which hosts are permitted to act as network gateways. With no public PoC or KEV listing yet but a Critical network-reachable rating, treat patching as urgent before exploit details emerge.
Affected
| Microsoft Windows — Internet Connection Sharing (ICS) component | — |
Estimated exposure
mass>1,000,000 Windows devices plausibly affected (ICS is a standard component across Windows editions on a >1B-device install base; only hosts with ICS/hotspot… — Windows runs on well over a billion devices and the ICS/SharedAccess component ships with those editions, so even the minority of hosts running connection sharing or the mobile hotspot feature implies far more than 1M potentially affected…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.