Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
A heap-based buffer overflow vulnerability exists in Windows IKE (Internet Key Exchange) Extension. An authenticated attacker can send a specially crafted IKE protocol message over the network to execute arbitrary code with SYSTEM-level privileges. The vulnerability affects Windows 10, Windows 11, and Windows Server 2019/2022/2025 systems. Microsoft has released patches for all affected versions. Exploitation is considered less likely but requires only valid user credentials and network access to the IKE service port.
- Valid user or service account credentials
- Network access to IKE protocol port (typically UDP 500/4500)
- Target system must have IKE Extension active or configured to use IKE for VPN/IPsec
Patching may require device reboot — plan for process interruption
/api/v1/advisories/a920cafc-3430-41c8-812b-094949ffad2bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.