CVE-2026-72983
9.8Microsoft · Windows
A use after free vulnerability in Windows Internet Connection Sharing (ICS) allows an unauthenticated, remote attacker to execute arbitrary code on the target system.
Executive summary
A critical use after free vulnerability in Windows Internet Connection Sharing (ICS) poses a severe risk of remote code execution, requiring immediate attention.
Vulnerability
This is a use after free flaw (CWE-416) within the Windows Internet Connection Sharing (ICS) component. It allows an unauthenticated attacker to trigger a memory corruption state over a network, potentially leading to remote code execution.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. Successful exploitation grants an attacker full control over the affected system, which could lead to complete data compromise, unauthorized access to sensitive corporate networks, and significant operational disruption. Given the ability to execute code without authentication, this flaw represents an extreme risk to enterprise security posture.
Remediation
Immediate Action: Apply the vendor-provided security updates immediately to the affected versions of Windows 10 and Windows 11 as detailed in the Microsoft Security Update Guide.
Proactive Monitoring: Monitor network traffic for anomalous behavior targeting the ICS service, specifically looking for unexpected inbound connections or unusual packet structures associated with the Internet Connection Sharing feature.
Compensating Controls: Disable the Internet Connection Sharing service on systems where it is not required to reduce the attack surface. Deploy network-level protections or host-based firewalls to restrict access to the service if patching cannot be performed instantly.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for remote code execution, organizations must prioritize patching all affected Windows workstations and servers. The ease of exploitability via the network makes this a high-priority item for IT administrators. If updates cannot be deployed immediately, isolating vulnerable systems from the network is the most effective temporary mitigation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section