Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-69429Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability exists in Windows IKE (Internet Key Exchange) Extension. An authenticated attacker can send a specially crafted IKE protocol message over the network to execute arbitrary code with SYSTEM-level privileges. The vulnerability affects Windows 10, Windows 11, and Windows Server 2019/2022/2025 systems. Microsoft has released patches for all affected versions. Exploitation is considered less likely but requires only valid user credentials and network access to the IKE service port.

What this means
What could happen
An attacker with valid credentials could exploit a buffer overflow in Windows IKE (Internet Key Exchange) to run arbitrary commands on servers and workstations, potentially gaining control of the system and any OT devices it communicates with.
Who's at risk
This affects Windows servers and workstations across utilities and water authorities that run remote access infrastructure, VPNs, or site-to-site connectivity using IKE/IPsec. Engineers and IT staff accessing production systems remotely are at risk, as well as any engineering workstations or HMI servers configured for IKE-based VPN connections. Windows Server 2019, 2022, and 2025 are commonly deployed as gateway or remote access servers in industrial networks.
How it could be exploited
An attacker with valid user or service account credentials sends a specially crafted IKE protocol packet to a Windows system running the vulnerable IKE Extension. The heap buffer overflow in the IKE handler allows the attacker to overwrite memory and execute arbitrary code with the privileges of the IKE service (typically SYSTEM on servers). The attack requires network access to the IKE port and authenticated credentials.
Prerequisites
  • Valid user or service account credentials
  • Network access to IKE protocol port (typically UDP 500/4500)
  • Target system must have IKE Extension active or configured to use IKE for VPN/IPsec
Remotely exploitableRequires valid credentials (reduces but does not eliminate risk)Affects critical IT infrastructure used by OT staffRuns with high system privileges
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/8
Do now
0/1
WORKAROUNDRestrict network access to IKE ports (UDP 500/4500) to only authorized VPN or remote access systems; block untrusted external connections at the firewall
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9245 or later via Windows Update
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5622 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later via Windows Update
All products
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later via Windows Update
HOTFIXUpdate Windows 10 Version 21H2 systems to Build 10.0.19044.7725 or later via Windows Update
HOTFIXUpdate Windows 10 Version 22H2 systems to Build 10.0.19045.7725 or later via Windows Update
HOTFIXUpdate Windows 11 systems to their respective fixed builds (23H2: 10.0.22631.7582, 24H2: 10.0.26100.9445, 25H2: 10.0.26200.9445, 26H1: 10.0.28000.2954) via Windows Update
API: /api/v1/advisories/a920cafc-3430-41c8-812b-094949ffad2b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.