Important CVSS 7.5 EPSS 0.01187 🔬 Patch diffed 2026-05 archive

Executive Summary

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

Overview

7.5
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Exploitation Unlikely
MS Exploit Likelihood
Category Denial of Service
Released May 12 2026
Last Updated May 12 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01187 — 0.65121 percentile
NVD CVSS 7.5 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
None
INTEGRITY
None
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.5

EPSS Score

0.01187
probability of exploitation in the next 30 days
0.65121 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

23 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5087537 (Security Update) Important Denial of Service Yes
Windows 10 Version 1607 for x64-based Systems 5087537 (Security Update) Important Denial of Service Yes
Windows 10 Version 1809 for 32-bit Systems 5087538 (Security Update) Important Denial of Service Yes
Windows 10 Version 1809 for x64-based Systems 5087538 (Security Update) Important Denial of Service Yes
Windows 10 Version 21H2 for 32-bit Systems 5087544 (Security Update) Important Denial of Service Yes
Windows 10 Version 21H2 for ARM64-based Systems 5087544 (Security Update) Important Denial of Service Yes
Windows 10 Version 21H2 for x64-based Systems 5087544 (Security Update) Important Denial of Service Yes
Windows 10 Version 22H2 for 32-bit Systems 5094127 (Security Update) Important Denial of Service Yes
Windows 10 Version 22H2 for ARM64-based Systems 5094127 (Security Update) Important Denial of Service Yes
Windows 10 Version 22H2 for x64-based Systems 5094127 (Security Update) Important Denial of Service Yes
Windows 11 Version 23H2 for ARM64-based Systems 5087420 (Security Update) Important Denial of Service Yes
Windows 11 Version 23H2 for x64-based Systems 5093998 (Security Update) Important Denial of Service Yes
Windows 11 Version 24H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5082063 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 24H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5082063 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5083769 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 25H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5083769 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5089548 (Security Update) Important Denial of Service Yes
Windows 11 version 26H1 for x64-based Systems 5089548 (Security Update) Important Denial of Service Yes
Windows Server 2012 5087470 (Monthly Rollup) Important Denial of Service Yes
Windows Server 2012 (Server Core installation) 5087470 (Monthly Rollup) Important Denial of Service Yes
Windows Server 2012 R2 5087471 (Monthly Rollup) Important Denial of Service Yes
Windows Server 2012 R2 (Server Core installation) 5087471 (Monthly Rollup) Important Denial of Service Yes
Windows Server 2016 5087537 (Security Update) Important Denial of Service Yes
Windows Server 2016 (Server Core installation) 5087537 (Security Update) Important Denial of Service Yes
Windows Server 2019 5087538 (Security Update) Important Denial of Service Yes
Windows Server 2019 (Server Core installation) 5087538 (Security Update) Important Denial of Service Yes
Windows Server 2022 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Denial of Service 5082142 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022 (Server Core installation) 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Denial of Service 5082142 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5087541 (Security Update) Important Denial of Service Yes

Patches

10 patches
Article Type Restart
5087537 Security Update Yes
5087538 Security Update Yes
5087544 Security Update Yes
5094127 Security Update Yes
5087420 Security Update Yes
5093998 Security Update Yes
5089548 Security Update Yes
5087470 Monthly Rollup Yes
5087471 Monthly Rollup Yes
5087541 Security Update Yes

Patch Diff

ghidriff · ikeext.dll (KB5089549)

Memory leak (CWE-401, missing release of memory after effective lifetime) in the Windows IKE Protocol ikeext.dll Main-Mode attribute parser, unauthenticated network denial of service (Important, AV:N, CVSS 7.5). During IKE Main-Mode negotiation, IkeParseMMAttributes parses the incoming SA attribute payload and copies incoming attribute data (IkeCopyIncomingDataQuiet) into a work buffer referenced from its attribute structure at param_2 + 0xc. PRE: when parsing/validation failed, the function returned via IkeReturnError WITHOUT freeing that buffer, leaking it on every request that reached the error path. Because IKE processes negotiation packets over the network without authentication, an attacker can repeatedly send crafted Main-Mode packets that each leak the buffer, driving the IKEEXT service toward memory exhaustion and DoS. Diff of ikeext.dll 10.0.26100.8328 -> .8457 (May 12 2026, KB5089549) shows IkeParseMMAttributes as the code-changed function: gated behind CFR flag Feature_1865663801, the fix adds WfpMemFree((longlong *)(param_2 + 0xc)) before the IkeReturnError call, releasing the incoming attribute buffer on the return path so repeated Main-Mode packets no longer accumulate leaked memory.

Pre-patch version 10.0.26100.8328 Download
Post-patch version 10.0.26100.8457 Download
Function Address Change Note
IkeParseMMAttributes code change code (attribute buffer now freed on error return, CFR-gated) Pre: the incoming Main-Mode attribute buffer (param_2 + 0xc), populated via IkeCopyIncomingDataQuiet, was leaked when the function returned via IkeReturnError on a parse/validation error. Post (Feature_1865663801): adds WfpMemFree((longlong *)(param_2 + 0xc)) before IkeReturnError so the buffer is released on the return path.
IkeCopyIncomingDataQuiet / WfpMemFree code change code (allocation source / release primitive touched in same update) IkeCopyIncomingDataQuiet copies the incoming attribute data that was leaked; WfpMemFree is the release primitive now invoked on the error path.
Feature_1865663801 gate added (CFR gate) CFR flag gating the WfpMemFree release in IkeParseMMAttributes; the original leaking path still ships when the flag is disabled.
View full diff report View RCA report

Attack Path

Crafted IKE Main-Mode packets leak the attribute buffer on each error return, exhausting IKEEXT memory

Attack path for CVE-2026-35424 Crafted IKE Main-Mode packets leak the attribute buffer on each error return, exhausting IKEEXT memory 01 — ENTRY Attacker sends crafted IKE Main-Mode packets over the network ikeext!IkeParseMMAttributes parses the incoming SA attribute payload. AV:N / PR:N / UI:N (unauthenticated network, UDP 500/4500). 02 — CONTROLLED INPUT Copies incoming attribute data, then hits an error path IkeCopyIncomingDataQuiet populates the attribute buffer at param_2 + 0xc; a parse/validation failure returns via IkeReturnError. 03 — MISSING CHECK Attribute buffer leaked on error return (CWE-401) Pre-patch the buffer at param_2 + 0xc is not freed before IkeReturnError, leaking memory on every failed negotiation. 04 — IMPACT Repeated leaks -> memory exhaustion -> DoS An unauthenticated attacker replays crafted Main-Mode packets to accumulate leaked buffers until the IKEEXT service / system is starved of memory (A:H).

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments

Microsoft