CVE-2026-35424 — Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
Executive Summary
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5087537 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5087537 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5087538 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5087538 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5087544 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5087544 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5087544 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5094127 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5094127 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5094127 (Security Update) |
Important | Denial of Service | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5087420 (Security Update) |
Important | Denial of Service | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5093998 (Security Update) |
Important | Denial of Service | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5082063 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 24H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5082063 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5083769 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 25H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Denial of Service 5083769 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5089548 (Security Update) |
Important | Denial of Service | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5089548 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2012 | 5087470 (Monthly Rollup) |
Important | Denial of Service | Yes |
| Windows Server 2012 (Server Core installation) | 5087470 (Monthly Rollup) |
Important | Denial of Service | Yes |
| Windows Server 2012 R2 | 5087471 (Monthly Rollup) |
Important | Denial of Service | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5087471 (Monthly Rollup) |
Important | Denial of Service | Yes |
| Windows Server 2016 | 5087537 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2016 (Server Core installation) | 5087537 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 | 5087538 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 (Server Core installation) | 5087538 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2022 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Denial of Service 5082142 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022 (Server Core installation) 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Denial of Service 5082142 Base: 7.5 Temporal: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5087541 (Security Update) |
Important | Denial of Service | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5087537 |
Security Update | Yes |
5087538 |
Security Update | Yes |
5087544 |
Security Update | Yes |
5094127 |
Security Update | Yes |
5087420 |
Security Update | Yes |
5093998 |
Security Update | Yes |
5089548 |
Security Update | Yes |
5087470 |
Monthly Rollup | Yes |
5087471 |
Monthly Rollup | Yes |
5087541 |
Security Update | Yes |
Patch Diff
Memory leak (CWE-401, missing release of memory after effective lifetime) in the Windows IKE Protocol ikeext.dll Main-Mode attribute parser, unauthenticated network denial of service (Important, AV:N, CVSS 7.5). During IKE Main-Mode negotiation, IkeParseMMAttributes parses the incoming SA attribute payload and copies incoming attribute data (IkeCopyIncomingDataQuiet) into a work buffer referenced from its attribute structure at param_2 + 0xc. PRE: when parsing/validation failed, the function returned via IkeReturnError WITHOUT freeing that buffer, leaking it on every request that reached the error path. Because IKE processes negotiation packets over the network without authentication, an attacker can repeatedly send crafted Main-Mode packets that each leak the buffer, driving the IKEEXT service toward memory exhaustion and DoS. Diff of ikeext.dll 10.0.26100.8328 -> .8457 (May 12 2026, KB5089549) shows IkeParseMMAttributes as the code-changed function: gated behind CFR flag Feature_1865663801, the fix adds WfpMemFree((longlong *)(param_2 + 0xc)) before the IkeReturnError call, releasing the incoming attribute buffer on the return path so repeated Main-Mode packets no longer accumulate leaked memory.
| Function | Address | Change | Note |
|---|---|---|---|
IkeParseMMAttributes |
code change |
code (attribute buffer now freed on error return, CFR-gated) | Pre: the incoming Main-Mode attribute buffer (param_2 + 0xc), populated via IkeCopyIncomingDataQuiet, was leaked when the function returned via IkeReturnError on a parse/validation error. Post (Feature_1865663801): adds WfpMemFree((longlong *)(param_2 + 0xc)) before IkeReturnError so the buffer is released on the return path. |
IkeCopyIncomingDataQuiet / WfpMemFree |
code change |
code (allocation source / release primitive touched in same update) | IkeCopyIncomingDataQuiet copies the incoming attribute data that was leaked; WfpMemFree is the release primitive now invoked on the error path. |
Feature_1865663801 |
gate |
added (CFR gate) | CFR flag gating the WfpMemFree release in IkeParseMMAttributes; the original leaking path still ships when the flag is disabled. |
Attack Path
Crafted IKE Main-Mode packets leak the attribute buffer on each error return, exhausting IKEEXT memory
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Microsoft