Windows TCP/IP Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-59132Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A null pointer dereference in the Windows TCP/IP stack allows an unauthenticated attacker to cause a denial of service by sending specially crafted network packets. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes for all supported versions.
What this means
What could happen
An attacker on the network can send specially crafted TCP/IP packets to crash the TCP/IP stack, causing the affected Windows system to stop responding to network traffic. This could disrupt any critical process relying on network connectivity, including remote access to PLCs, HMI systems, or data historian servers.
Who's at risk
This affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems. In utilities and water authorities, this is critical for any Windows-based SCADA servers, HMI systems, engineering workstations, historians, and remote terminal units or gateways that rely on network connectivity.
How it could be exploited
An attacker sends malformed TCP/IP packets to a vulnerable Windows system from anywhere on the network. The null pointer dereference in the TCP/IP driver causes a kernel panic, forcing a reboot. No credentials or local access are needed.
Prerequisites
- Network access to the affected Windows system
- No credentials required
- No special configuration required
remotely exploitableno authentication requiredlow complexityaffects network availability
Exploitability
Some exploitation risk — EPSS score 1.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to Windows systems running TCP/IP by configuring firewall rules on network edge and perimeter devices to limit inbound traffic to only trusted networks and necessary services.
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply Microsoft 2026-Aug security update to all affected Windows systems. For Windows Server 2019, update to Build 10.0.17763.9115 or later. For Windows Server 2022, update to Build 10.0.20348.5499 or later. For Windows Server 2025, update to Build 10.0.26100.33296 or later.
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate critical Windows systems (engineering workstations, data historians, remote access gateways) from untrusted network segments.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b0d72ecf-2d0c-4c50-8c12-9ba7a67112b6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.