ZeroHour

CVE-2026-72983

mass

Use-after-free RCE in Windows Internet Connection Sharing (ICS)

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-72983 is a use-after-free memory-safety flaw (CWE-416) in the Windows Internet Connection Sharing (ICS) component, rated Critical (CVSS 9.8) because it is reachable over the network by an unauthenticated attacker with no user interaction. It is triggered by sending crafted network traffic to a Windows host running ICS — for example a machine sharing its connection or acting as a gateway/hotspot — causing the service to use memory that has already been freed. A successful attack lets the adversary execute arbitrary code on the affected host, giving full confidentiality, integrity and availability impact (C:H/I:H/A:H). Affected are Windows systems on which ICS is enabled and network-reachable; specific Windows version ranges are not provided in the source data, and Microsoft shipped the fix in its September 2026 security updates. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists yet; EPSS puts the 30-day exploitation probability at 0.9% (58th percentile).

What to do: Apply Microsoft's September 2026 security updates on all Windows systems, prioritizing hosts that have Internet Connection Sharing or the mobile hotspot feature enabled or that sit on untrusted/exposed network segments. Where ICS is not needed, disable the SharedAccess service and restrict which hosts are permitted to act as network gateways. With no public PoC or KEV listing yet but a Critical network-reachable rating, treat patching as urgent before exploit details emerge.

Affected
Microsoft Windows — Internet Connection Sharing (ICS) component
Estimated exposure
mass>1,000,000 Windows devices plausibly affected (ICS is a standard component across Windows editions on a >1B-device install base; only hosts with ICS/hotspot… — Windows runs on well over a billion devices and the ICS/SharedAccess component ships with those editions, so even the minority of hosts running connection sharing or the mobile hotspot feature implies far more than 1M potentially affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.