Windows TCP/IP Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-69588Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A memory management flaw in the Windows TCP/IP stack allows an unauthenticated attacker on the network to send specially crafted packets that cause the operating system to exhaust memory resources, resulting in denial of service. The vulnerability affects Windows Server 2022, Windows Server 2025, and Windows 11 systems across all supported versions and architectures.

What this means
What could happen
An attacker on your network can crash Windows servers and workstations by exploiting a flaw in the TCP/IP stack, causing loss of network connectivity and stopping any services running on those machines.
Who's at risk
Windows Server 2022 and 2025, Windows 11 workstations, and any IT infrastructure that depends on these systems for network services, domain control, or data processing. This affects any municipal utility using Windows-based SCADA workstations, HMI servers, or engineering stations connected to external networks.
How it could be exploited
An attacker sends crafted TCP/IP packets over the network to a Windows machine. The packets trigger improper memory handling in the TCP/IP driver, consuming memory until the system runs out of resources and becomes unresponsive or crashes.
Prerequisites
  • Network access to the target Windows machine
  • No authentication required
remotely exploitableno authentication requiredlow complexity
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict inbound network access to your Windows servers from untrusted networks using firewall rules
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate Windows Server 2022 to build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 11 (all versions) to the latest build specified for your version (23H2, 24H2, 25H2, or 26H1)
API: /api/v1/advisories/a35734bb-1fec-4d16-a761-faa6dae8e2c7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.