Windows TCP/IP Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-62792Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A stack-based buffer overflow exists in the Windows TCP/IP stack that allows an unauthenticated attacker to execute arbitrary code over the network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures. Exploitation requires sending a specially crafted network packet but does not require user interaction or elevated privileges. Microsoft has released patches for all affected versions as part of the August 2026 security update.

What this means
What could happen
An attacker could run arbitrary code on Windows servers or workstations via the TCP/IP stack, potentially gaining full control of the machine and any connected OT systems or networks it supports.
Who's at risk
IT teams and OT managers at utilities with Windows-based engineering workstations, HMIs (human-machine interfaces), data historians, or SCADA servers should prioritize patching. This includes any Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems used for industrial process monitoring or control.
How it could be exploited
An attacker sends a specially crafted network packet to the TCP/IP stack on a vulnerable Windows system. The packet triggers a stack-based buffer overflow that allows the attacker to execute arbitrary code with the privileges of the network service processing the packet.
Prerequisites
  • Network connectivity to the affected Windows system
  • Target must be running a vulnerable version of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025
  • No authentication required
Remotely exploitableNo authentication requiredStack-based buffer overflowTCP/IP is a fundamental network service
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXFor Windows Server 2019 (all installations), update to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXFor Windows Server 2022 (all installations), update to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXFor Windows Server 2025 (all installations), update to Build 10.0.26100.33296 or later
All products
HOTFIXApply Microsoft's August 2026 security update to all Windows 10, Windows 11, and Windows Server systems
HOTFIXFor Windows 10 Version 1809 (32-bit and x64), update to Build 10.0.17763.9115 or later
HOTFIXFor Windows 10 Version 21H2, 22H2 (all architectures), update to the corresponding fixed build numbers (19044.7663 or 19045.7663)
HOTFIXFor Windows 11 (all versions and architectures), update to the corresponding fixed build numbers (22631.7517, 26200.9168, 26200.9106, or 28000.2704 depending on version)
Long-term hardening
0/1
HARDENINGImplement network segmentation to limit exposure of critical OT workstations and SCADA servers to necessary network traffic only
API: /api/v1/advisories/3904368d-1a09-4137-bc0e-b249ab41213f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows TCP/IP Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse