CVE-2026-33824

9.5 CISA KEV

Microsoft · Windows

A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.

Executive summary

A critical double-free vulnerability in the Windows IKE Extension enables unauthenticated remote code execution, posing a severe threat to all affected Windows systems.

Vulnerability

This is a double-free vulnerability within the Windows IKE (Internet Key Exchange) Extension. An unauthenticated attacker can trigger this flaw over the network to achieve arbitrary code execution.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk of full system compromise. Because the attack is network-based and does not require authentication, it represents a significant threat to internal and external-facing systems, potentially leading to widespread data exfiltration or malware deployment.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the April 2026 update cycle to resolve the double-free condition.

Proactive Monitoring: Monitor network traffic for anomalous IKEv2 packet patterns and review system logs for crashes or unexpected service restarts related to the IKEEXT service.

Compensating Controls: Restrict network access to IKE/IPsec endpoints to known, trusted IP addresses using network-level firewalls until patches can be applied.

Exploitation status

Public Exploit Available: Unknown — while there are public GitHub proof-of-concept repositories, there is no evidence of weaponized modules in curated sources like Metasploit or ExploitDB.

Analyst recommendation

This vulnerability is highly critical due to the potential for unauthenticated remote code execution. Administrators should deploy the Microsoft security updates as a matter of high urgency across all affected Windows endpoints and servers.

More Microsoft CVEs